Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
6351 9.1 緊急
Network
Angeet ES3 KVM Firmware AngeetのES3 KVM FirmwareにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-32298 2026-04-30 12:13 2026-03-17 Show GitHub Exploit DB Packet Storm
6352 7.5 重要
Network
オラクル Oracle Financial Services Customer Screening オラクルのOracle Financial Services Customer Screeningにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-34320 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
6353 5.8 警告
Network
Pavel Zbornik (pavelzbornik) whisperX REST API Pavel Zbornik (pavelzbornik)のwhisperX REST APIにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-34981 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
6354 7.5 重要
Network
Distribution Distribution Distributionにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-35172 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
6355 7.5 重要
Network
UnJS Team defu UnJS Teamのdefuにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-35209 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
6356 7.5 重要
Network
オラクル Oracle Financial Services Transaction Filtering オラクルのOracle Financial Services Transaction Filteringにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-35231 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
6357 6.3 警告
Local
Flatpak XDG Desktop Portal (xdg-desktop-portal) FlatpakのXDG Desktop Portal (xdg-desktop-portal)におけるUNIX Symbolic Link のフォローに関する脆弱性 CWE-61
UNIX Symbolic Link のフォロー
CVE-2026-40354 2026-04-30 12:13 2026-04-11 Show GitHub Exploit DB Packet Storm
6358 5.3 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40448 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
6359 6.6 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40449 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
6360 6.6 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40450 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
351591 - netgear rp114 Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences. NVD-CWE-Other
CVE-2004-2032 2017-07-11 10:31 2004-05-24 Show GitHub Exploit DB Packet Storm
351592 - orenosv orenosv_http_ftp_server Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. NVD-CWE-Other
CVE-2004-2033 2017-07-11 10:31 2004-05-26 Show GitHub Exploit DB Packet Storm
351593 - wildtangent webdriver Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename. NVD-CWE-Other
CVE-2004-2034 2017-07-11 10:31 2004-01-29 Show GitHub Exploit DB Packet Storm
351594 - minishare minimal_http_server MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences. NVD-CWE-Other
CVE-2004-2035 2017-07-11 10:31 2004-05-26 Show GitHub Exploit DB Packet Storm
351595 - jportal jportal_web_portal SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter. NVD-CWE-Other
CVE-2004-2036 2017-07-11 10:31 2004-05-28 Show GitHub Exploit DB Packet Storm
351596 - mollensoft_software lightweight_ftp_server Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstr… NVD-CWE-Other
CVE-2004-2037 2017-07-11 10:31 2004-03-24 Show GitHub Exploit DB Packet Storm
351597 - neocrome land_down_under Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.p… NVD-CWE-Other
CVE-2004-2038 2017-07-11 10:31 2004-05-29 Show GitHub Exploit DB Packet Storm
351598 - e107 e107 e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and ot… NVD-CWE-Other
CVE-2004-2039 2017-07-11 10:31 2004-05-29 Show GitHub Exploit DB Packet Storm
351599 - e107 e107 Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to … NVD-CWE-Other
CVE-2004-2040 2017-07-11 10:31 2004-05-29 Show GitHub Exploit DB Packet Storm
351600 - - - PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web se… NVD-CWE-Other
CVE-2004-2041 2017-07-11 10:31 2004-05-29 Show GitHub Exploit DB Packet Storm