Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5561 10 緊急
Network
マイクロソフト Azure AI Foundry Azure AI Foundry の特権昇格の脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-35435 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
5562 9.8 緊急
Network
coredns.io CoreDNS The CoreDNS AuthorsのCoreDNSにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-35579 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
5563 9.8 緊急
Network
Kestra Kestra KestraにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-38428 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
5564 7.2 重要
Network
Gotenberg, Inc. Gotenberg TheCodingMachineのGotenbergにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-39383 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
5565 8.8 重要
Network
Apache Software Foundation Apache NiFi Apache Software FoundationのApache NiFiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-39816 2026-05-11 11:10 2026-05-8 Show GitHub Exploit DB Packet Storm
5566 8.2 重要
Network
Quarkus Quarkus Quarkusにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-39852 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
5567 4.8 警告
Network
Linux Containers Incus Linux ContainersのIncusにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40243 2026-05-11 11:10 2026-05-6 Show GitHub Exploit DB Packet Storm
5568 7.5 重要
Network
Gotenberg, Inc. Gotenberg TheCodingMachineのGotenbergにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-40280 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
5569 8.8 重要
Network
Math.js Math.js Math.jsにおける動的に決定されたオブジェクト属性の不適切に制御された変更に関する脆弱性 CWE-915
動的に決定されたオブジェクト属性の不適切に制御された変更
CVE-2026-41139 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
5570 8.8 重要
Network
OpenEXR OpenEXR OpenEXRにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-41142 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346451 - namazu namazu Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit… NVD-CWE-Other
CVE-2001-1351 2017-10-10 10:30 2001-12-25 Show GitHub Exploit DB Packet Storm
346452 - namazu namazu Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index f… NVD-CWE-Other
CVE-2001-1352 2017-10-10 10:30 2001-12-27 Show GitHub Exploit DB Packet Storm
346453 - caldera volution Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Troja… NVD-CWE-Other
CVE-2001-1359 2017-10-10 10:30 2001-06-8 Show GitHub Exploit DB Packet Storm
346454 - oracle application_server Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error… NVD-CWE-Other
CVE-2001-1372 2017-10-10 10:30 2002-02-6 Show GitHub Exploit DB Packet Storm
346455 - zonelabs zonealarm MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send potentially dangerous at… NVD-CWE-Other
CVE-2001-1373 2017-10-10 10:30 2001-07-18 Show GitHub Exploit DB Packet Storm
346456 - don_libes
conectiva
redhat
expect
linux
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd. NVD-CWE-Other
CVE-2001-1374 2017-10-10 10:30 2001-07-19 Show GitHub Exploit DB Packet Storm
346457 - stunnel
engardelinux
mandrakesoft
redhat
stunnel
secure_linux
mandrake_linux
linux
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. NVD-CWE-Other
CVE-2002-0002 2017-10-10 10:30 2002-01-31 Show GitHub Exploit DB Packet Storm
346458 - gnu groff Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system. NVD-CWE-Other
CVE-2002-0003 2017-10-10 10:30 2002-02-27 Show GitHub Exploit DB Packet Storm
346459 - caldera
debian
freebsd
mandrakesoft
netbsd
redhat
slackware
suse
openlinux_server
openlinux_workstation
debian_linux
freebsd
mandrake_linux
netbsd
linux
slackware_linux
suse_linux
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. NVD-CWE-Other
CVE-2002-0004 2017-10-10 10:30 2002-02-27 Show GitHub Exploit DB Packet Storm
346460 - aol instant_messenger Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). NVD-CWE-Other
CVE-2002-0005 2017-10-10 10:30 2002-01-31 Show GitHub Exploit DB Packet Storm