Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1121 7.5 重要
Network
follow-redirects project Follow Redirects Follow Redirects projectのFollow Redirectsにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-40895 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1122 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-40907 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1123 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-40908 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1124 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40909 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1125 5.4 警告
Network
Docmost Docmost Docmostにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40927 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1126 5.4 警告
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40928 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1127 5.4 警告
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40929 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1128 7.8 重要
Local
node-modules compressing node-modulesのcompressingにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-40931 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1129 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおける推測可能な CAPTCHA の脆弱性 CWE-804
推測可能な CAPTCHA
CVE-2026-40935 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
1130 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41055 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313391 - sun nfs Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0. NVD-CWE-Other
CVE-1999-0084 2024-08-2 06:35 1990-05-1 Show GitHub Exploit DB Packet Storm
313392 - sun sunos Solaris ufsrestore buffer overflow. NVD-CWE-Other
CVE-1999-0069 2024-08-2 05:35 1998-04-29 Show GitHub Exploit DB Packet Storm
313393 - isc
netscape
caldera
bsdi
redhat
nec
inn
news_server
openlinux
bsd_os
linux
goah_networksv
goah_intrasv
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. NVD-CWE-Other
CVE-1999-0043 2024-08-2 05:35 1996-12-4 Show GitHub Exploit DB Packet Storm
313394 - sun solaris Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka Sys… NVD-CWE-Other
CVE-1999-1588 2024-08-2 04:35 1999-12-31 Show GitHub Exploit DB Packet Storm
313395 - ssh ssh Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. NVD-CWE-Other
CVE-1999-0013 2024-08-2 04:35 1998-01-22 Show GitHub Exploit DB Packet Storm
313396 - - - The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks - CVE-2024-6412 2024-08-2 03:35 2024-07-31 Show GitHub Exploit DB Packet Storm
313397 - - - It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface… - CVE-2024-6873 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
313398 - - - A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a … - CVE-2024-6242 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
313399 - - - In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /ins… CWE-304
 Missing Critical Step in Authentication
CVE-2024-6040 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
313400 - - - Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based E… - CVE-2024-41961 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm