Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1 7.2 重要
Network
株式会社GROWI GROWI GROWIにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-41951 2026-05-11 15:29 2026-05-11 Show GitHub Exploit DB Packet Storm
2 7.4 重要
Network
株式会社EPG iOSアプリ「くら寿司 公式アプリ」
Androidアプリ「くら寿司 公式アプリ」
スマートフォンアプリ「くら寿司 公式アプリ」における証明書検証不備の脆弱性 New CWE-Other
その他
CVE-2026-41872 2026-05-11 12:52 2026-05-11 Show GitHub Exploit DB Packet Storm
3 3.3
Local
ちとらソフト Lhaz+
Lhaz
LhazおよびLhaz+におけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-41530 2026-05-11 12:39 2026-05-11 Show GitHub Exploit DB Packet Storm
4 3.3
Local
X.Org Foundation libxpm libXpmにおける境界外読み取りの脆弱性 New CWE-Other
その他
CVE-2026-4367 2026-05-11 12:18 2026-05-11 Show GitHub Exploit DB Packet Storm
5 7.3 重要
Network
yeti-platform yeti yeti-platformのyetiにおけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2024-46507 2026-05-11 11:13 2026-05-8 Show GitHub Exploit DB Packet Storm
6 7.5 重要
Network
yeti-platform yeti yeti-platformのyetiにおけるハードコードされた認証情報の使用に関する脆弱性 New CWE-798
ハードコードされた認証情報の使用
CVE-2024-46508 2026-05-11 11:12 2026-05-8 Show GitHub Exploit DB Packet Storm
7 9.8 緊急
Network
Frappe ERPNext FrappeのERPNextにおけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2026-38431 2026-05-11 11:12 2026-05-5 Show GitHub Exploit DB Packet Storm
8 6.1 警告
Network
Frappe ERPNext FrappeのERPNextにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-38432 2026-05-11 11:12 2026-05-5 Show GitHub Exploit DB Packet Storm
9 9.1 緊急
Network
CHORNY Apache::Session CHORNYのApache::Sessionにおける有効期限後または解放後のリソースの操作に関する脆弱性 New CWE-672
有効期限後または解放後のリソースの操作
CVE-2013-10075 2026-05-11 11:12 2026-05-8 Show GitHub Exploit DB Packet Storm
10 9.8 緊急
Network
PHPOffice PhpSpreadsheet PHPOfficeのPhpSpreadsheetにおける複数の脆弱性 New CWE-502
CWE-918
CVE-2026-34084 2026-05-11 11:12 2026-05-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346871 - apple terminal
mac_os_x
mac_os_x_server
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences. NVD-CWE-Other
CVE-2005-1341 2011-03-8 11:21 2005-05-4 Show GitHub Exploit DB Packet Storm
346872 - apple terminal
mac_os_x
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands. NVD-CWE-Other
CVE-2005-1342 2011-03-8 11:21 2005-05-4 Show GitHub Exploit DB Packet Storm
346873 - phpmyadmin phpmyadmin The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script. NVD-CWE-Other
CVE-2005-1392 2011-03-8 11:21 2005-05-3 Show GitHub Exploit DB Packet Storm
346874 - freebsd freebsd The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications t… NVD-CWE-Other
CVE-2005-1406 2011-03-8 11:21 2005-05-6 Show GitHub Exploit DB Packet Storm
346875 - soft3304 04webserver Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder. NVD-CWE-Other
CVE-2005-1416 2011-03-8 11:21 2005-05-3 Show GitHub Exploit DB Packet Storm
346876 - stefan_ritt elog_web_logbook ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL. NVD-CWE-Other
CVE-2005-0440 2011-03-8 11:20 2005-05-2 Show GitHub Exploit DB Packet Storm
346877 - mediawiki mediawiki Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script. NVD-CWE-Other
CVE-2005-0534 2011-03-8 11:20 2005-05-2 Show GitHub Exploit DB Packet Storm
346878 - mediawiki
gentoo
mediawiki
linux
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users. NVD-CWE-Other
CVE-2005-0535 2011-03-8 11:20 2005-02-22 Show GitHub Exploit DB Packet Storm
346879 - mediawiki mediawiki Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to… NVD-CWE-Other
CVE-2005-0536 2011-03-8 11:20 2005-05-2 Show GitHub Exploit DB Packet Storm
346880 - kmint21_software golden_ftp_server Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command. NVD-CWE-Other
CVE-2005-0634 2011-03-8 11:20 2005-05-2 Show GitHub Exploit DB Packet Storm