Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5501 7.2 重要
Network
Dolibarr ERP & CRM dolibarr erp/crm Dolibarr ERP & CRMのdolibarr erp/crmにおける複数の脆弱性 CWE-94
CWE-95
CVE-2026-22666 2026-04-27 11:29 2026-04-7 Show GitHub Exploit DB Packet Storm
5502 9.8 緊急
Network
Weaver Software Weaver e cology Weaver SoftwareのWeaver e cologyにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-22679 2026-04-27 11:29 2026-04-7 Show GitHub Exploit DB Packet Storm
5503 8.8 重要
Local
PackageKit Project PackageKit PackageKit ProjectのPackageKitにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41651 2026-04-27 11:29 2026-04-22 Show GitHub Exploit DB Packet Storm
5504 4.4 警告
Local
libjxl project libjxl libjxl projectのlibjxlにおける初期化されていないリソースの使用に関する脆弱性 CWE-908
初期化されていないリソースの使用
CVE-2025-12474 2026-04-27 11:28 2026-02-11 Show GitHub Exploit DB Packet Storm
5505 7.5 重要
Network
FirebirdSQL Firebird FirebirdSQLのFirebirdにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2025-65104 2026-04-27 11:28 2026-04-17 Show GitHub Exploit DB Packet Storm
5506 6.7 警告
Local
マイクロソフト Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 10 22h2
Microsoft Wind…
UEFI セキュア ブートのセキュリティ機能バイパスの脆弱性 CWE-807
セキュリティ決定の信頼できない入力への依存
CVE-2026-0390 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
5507 4.3 警告
Network
wolfssh wolfssh wolfsshにおける複数の脆弱性 CWE-125
CWE-126
CVE-2026-0930 2026-04-27 11:28 2026-04-20 Show GitHub Exploit DB Packet Storm
5508 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows COM サーバーの情報漏えいの脆弱性 CWE-843
型の取り違え
CVE-2026-20806 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
5509 4.6 警告
Physics
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows 回復環境のセキュリティ機能バイパスの脆弱性 CWE-212
保存または転送前の重要な情報の不適切な削除
CVE-2026-20928 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
5510 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 10 1809
Microsoft Windows 10 22h2
Microsoft Wind…
Windows Management サービスの特権昇格の脆弱性 CWE-362
競合状態
CVE-2026-20930 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349871 - the_palace the_palace_client Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string. NVD-CWE-Other
CVE-2004-0262 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349872 - jim_rees
shaun2k2
jim_rees_httpd
palmhttpd
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. NVD-CWE-Other
CVE-2004-0264 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349873 - francisco_burzi php-nuke Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in … NVD-CWE-Other
CVE-2004-0265 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349874 - evolutionx evolutionx Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet s… NVD-CWE-Other
CVE-2004-0268 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349875 - francisco_burzi php-nuke SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Sea… NVD-CWE-Other
CVE-2004-0269 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349876 - maxwebportal maxwebportal Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the Sen… NVD-CWE-Other
CVE-2004-0271 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349877 - maxwebportal maxwebportal This vulnerability is addressed in the following product release: MaxWebPortal, MaxWebPortal, 1.32 NVD-CWE-Other
CVE-2004-0271 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349878 - maxwebportal maxwebportal SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. NVD-CWE-Other
CVE-2004-0272 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349879 - bosdev bosdates SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. NVD-CWE-Other
CVE-2004-0275 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
349880 - bolintech dream_ftp_server Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. NVD-CWE-Other
CVE-2004-0277 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm