Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1051 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2012
Microso…
Data Deduplication Elevation of Privilege Vulnerability CWE-416
解放済みメモリの使用
CVE-2026-41095 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1052 9.8 緊急
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 11 25h2
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Microsoft Wind…
Windows DNS クライアントのリモートでコードが実行される脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-41096 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1053 6.7 警告
Local
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10 22h2
Microsoft Windows 11 25h2
Microsoft Windows Server 2022
Microsoft …
セキュア ブートのセキュリティ機能のバイパスの脆弱性 CWE-1329
アップデートができないコンポーネントへの依存
CVE-2026-41097 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1054 4.4 警告
Local
マイクロソフト Microsoft 365 Copilot Android 用の Microsoft 365 Copilot のスプーフィングの脆弱性 CWE-284
CWE-Other
CVE-2026-41100 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1055 5.5 警告
Local
マイクロソフト Microsoft Word Microsoft Edge for Android のスプーフィングの脆弱性 CWE-284
CWE-noinfo
CVE-2026-41101 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1056 5.5 警告
Local
マイクロソフト Microsoft PowerPoint Microsoft PowerPoint for Android のスプーフィングの脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-41102 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1057 7.4 重要
Network
Outlook.com Microsoft Edge Chromium Microsoft Edge (Chromium ベース) の情報漏えいの脆弱性 CWE-610
CWE-73
CVE-2026-41107 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1058 8.8 重要
Network
マイクロソフト Visual Studio Code GitHub Copilot と Visual Studio Code セキュリティ機能バイパスの脆弱性 CWE-74
インジェクション
CVE-2026-41109 2026-05-18 11:31 2026-05-12 Show GitHub Exploit DB Packet Storm
1059 7.4 重要
Network
Open Knowledge Foundation CKAN Open Knowledge FoundationのCKANにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-41132 2026-05-18 11:31 2026-05-13 Show GitHub Exploit DB Packet Storm
1060 6.1 警告
Network
Open Knowledge Foundation CKAN Open Knowledge FoundationのCKANにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-41255 2026-05-18 11:31 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318821 - linux linux_kernel The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activ… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2004-0427 2024-01-27 03:56 2004-07-7 Show GitHub Exploit DB Packet Storm
318822 - openbsd openbsd Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP P… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2004-0222 2024-01-27 03:55 2004-05-4 Show GitHub Exploit DB Packet Storm
318823 - freebsd freebsd Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count fo… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2002-0574 2024-01-27 03:55 2002-07-3 Show GitHub Exploit DB Packet Storm
318824 - proftpd
mandrakesoft
debian
conectiva
proftpd
mandrake_linux
debian_linux
linux
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2001-0136 2024-01-27 03:53 2001-03-12 Show GitHub Exploit DB Packet Storm
318825 5.8 MEDIUM
Network
chillcreations com_ccnewsletter Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in … CWE-22
Path Traversal
CVE-2010-0467 2024-01-27 02:44 2010-02-3 Show GitHub Exploit DB Packet Storm
318826 9.8 CRITICAL
Network
debian
canonical
lintian
debian_linux
ubuntu_linux
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive i… CWE-22
Path Traversal
CVE-2009-4013 2024-01-27 02:44 2010-02-3 Show GitHub Exploit DB Packet Storm
318827 7.5 HIGH
Network
ibm websphere_application_server IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. CWE-178
 Improper Handling of Case Sensitivity
CVE-2000-0497 2024-01-27 02:43 2000-06-8 Show GitHub Exploit DB Packet Storm
318828 7.5 HIGH
Network
unify ewave_servletexec Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. CWE-178
 Improper Handling of Case Sensitivity
CVE-2000-0498 2024-01-27 02:43 2000-06-8 Show GitHub Exploit DB Packet Storm
318829 7.5 HIGH
Network
bea weblogic_server The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. CWE-178
 Improper Handling of Case Sensitivity
CVE-2000-0499 2024-01-27 02:43 2000-06-8 Show GitHub Exploit DB Packet Storm
318830 7.1 HIGH
Local
iss blackice_server_protection
blackice_pc_protection
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2004-1714 2024-01-27 02:21 2004-08-11 Show GitHub Exploit DB Packet Storm