Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5651 6.5 警告
Network
pypdf project pypdf pypdf projectのpypdfにおける過度な反復の脆弱性 CWE-834
過度なイテレーション
CVE-2026-41313 2026-04-30 12:26 2026-04-22 Show GitHub Exploit DB Packet Storm
5652 6.5 警告
Network
pypdf project pypdf pypdf projectのpypdfにおける過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-41314 2026-04-30 12:26 2026-04-22 Show GitHub Exploit DB Packet Storm
5653 5.4 警告
Network
mintplexlabs anythingllm mintplexlabsのanythingllmにおける複数の脆弱性 CWE-116
CWE-1336
CWE-79
CVE-2026-41318 2026-04-30 12:26 2026-04-24 Show GitHub Exploit DB Packet Storm
5654 9.1 緊急
Network
The Kyverno Authors Kyverno The Kyverno AuthorsのKyvernoにおける複数の脆弱性 CWE-200
CWE-918
CVE-2026-41323 2026-04-30 12:26 2026-04-24 Show GitHub Exploit DB Packet Storm
5655 7.5 重要
Network
Patrick Juchli (patrickjuchli) Basic FTP Patrick Juchli (patrickjuchli)のBasic FTPにおける複数の脆弱性 CWE-400
CWE-770
CVE-2026-41324 2026-04-30 12:26 2026-04-24 Show GitHub Exploit DB Packet Storm
5656 8.8 重要
Network
getkirby kirby getkirbyのkirbyにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41325 2026-04-30 12:26 2026-04-24 Show GitHub Exploit DB Packet Storm
5657 9.9 緊急
Network
OpenClaw OpenClaw OpenClawにおける特権 API の不適切な使用に関する脆弱性 CWE-648
特権 API の不適切な使用
CVE-2026-41329 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
5658 4.4 警告
Local
OpenClaw OpenClaw OpenClawにおける変数の安全ではないデフォルト値への初期化に関する脆弱性 CWE-453
変数の安全ではないデフォルト値への初期化
CVE-2026-41330 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
5659 9.8 緊急
Network
socialengine socialengine socialengineにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-41460 2026-04-30 12:26 2026-04-23 Show GitHub Exploit DB Packet Storm
5660 8.5 重要
Network
socialengine socialengine socialengineにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41461 2026-04-30 12:26 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
351441 - jim_rees
shaun2k2
jim_rees_httpd
palmhttpd
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. NVD-CWE-Other
CVE-2004-0264 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351442 - francisco_burzi php-nuke Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in … NVD-CWE-Other
CVE-2004-0265 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351443 - evolutionx evolutionx Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet s… NVD-CWE-Other
CVE-2004-0268 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351444 - francisco_burzi php-nuke SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Sea… NVD-CWE-Other
CVE-2004-0269 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351445 - maxwebportal maxwebportal Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the Sen… NVD-CWE-Other
CVE-2004-0271 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351446 - maxwebportal maxwebportal This vulnerability is addressed in the following product release: MaxWebPortal, MaxWebPortal, 1.32 NVD-CWE-Other
CVE-2004-0271 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351447 - maxwebportal maxwebportal SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. NVD-CWE-Other
CVE-2004-0272 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351448 - bosdev bosdates SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. NVD-CWE-Other
CVE-2004-0275 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351449 - bolintech dream_ftp_server Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. NVD-CWE-Other
CVE-2004-0277 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm
351450 - ratbag dirt_track_racing
dirt_track_racing_australia
dirt_track_racing_sprint_cars
leadfoot
world_of_outlaws_sprint_cars
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet … NVD-CWE-Other
CVE-2004-0278 2017-07-11 10:30 2004-11-23 Show GitHub Exploit DB Packet Storm