Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1 - - IDrive Inc. IDrive Cloud Backup Client for Windows IDrive Cloud Backup Client for Windowsにおける権限昇格の脆弱性 New - CVE-2026-1995 2026-05-1 15:13 2026-04-30 Show GitHub Exploit DB Packet Storm
2 - - (複数のベンダ) (複数の製品) CISA ICS Advisory / ICS Medical Advisory(2026年04月28日) New - - 2026-05-1 14:31 2026-04-30 Show GitHub Exploit DB Packet Storm
3 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F456 Firmware Shenzhen Tenda Technology Co.,Ltd.のF456 Firmwareにおける複数の脆弱性 New CWE-119
CWE-120
CVE-2026-7100 2026-05-1 10:49 2026-04-27 Show GitHub Exploit DB Packet Storm
4 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F456 Firmware Shenzhen Tenda Technology Co.,Ltd.のF456 Firmwareにおける複数の脆弱性 New CWE-74
CWE-77
CVE-2026-7102 2026-05-1 10:49 2026-04-27 Show GitHub Exploit DB Packet Storm
5 7.2 重要
Local
click project click Pallets projectのClickにおけるコマンドインジェクションの脆弱性 New CWE-77
コマンドインジェクション
CVE-2026-7246 2026-05-1 10:49 2026-04-30 Show GitHub Exploit DB Packet Storm
6 7.8 重要
Local
LizardSystems Terminal Services Manager LizardSystemsのTerminal Services Managerにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2018-25259 2026-05-1 10:49 2026-04-22 Show GitHub Exploit DB Packet Storm
7 5.5 警告
Local
EZB Systems UltraISO EZB SystemsのUltraISOにおける境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2018-25267 2026-05-1 10:49 2026-04-22 Show GitHub Exploit DB Packet Storm
8 6.1 警告
Network
IceWarp, Inc. icewarp IceWarp, Inc.のicewarpにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25269 2026-05-1 10:49 2026-04-22 Show GitHub Exploit DB Packet Storm
9 8.1 重要
Network
レッドハット openshift ai レッドハットのopenshift aiにおける隔離または分類に関する脆弱性 New CWE-653
不適切な隔離または分類
CVE-2025-12805 2026-05-1 10:49 2026-03-26 Show GitHub Exploit DB Packet Storm
10 7.1 重要
Local
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおける複数の脆弱性 New CWE-121
CWE-787
CWE-787
CVE-2026-0819 2026-05-1 10:49 2026-03-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313541 - ethereal_group ethereal Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file. NVD-CWE-Other
CVE-2004-1761 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313542 - alan_ward a-cart SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. NVD-CWE-Other
CVE-2004-1873 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313543 - oscommerce oscommerce Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument. NVD-CWE-Other
CVE-2004-2021 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313544 - allwebscripts mysqlguest Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Com… NVD-CWE-Other
CVE-2004-2138 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313545 - phpx phpx PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which leaks the pathname in a database error message, as demonst… NVD-CWE-Other
CVE-2004-2362 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313546 - phpx phpx Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encode… NVD-CWE-Other
CVE-2004-2363 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313547 - phpx phpx Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator… NVD-CWE-Other
CVE-2004-2364 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313548 - - - PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath parameter. NVD-CWE-Other
CVE-2004-2368 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313549 - whitsoft_development slimftpd Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT. NVD-CWE-Other
CVE-2004-2418 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313550 - - - Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" se… NVD-CWE-Other
CVE-2004-2487 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm