Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1191 5.3 警告
Network
n8n-MCP n8n-MCP n8n-MCPにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-41495 2026-05-18 12:15 2026-05-8 Show GitHub Exploit DB Packet Storm
1192 6.2 警告
Local
マイクロソフト Microsoft 365 Copilot M365 Copilot for Desktop のスプーフィングの脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-41614 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1193 6.1 警告
Network
Open Source Geospatial Foundation MapServer Open Source Geospatial FoundationのMapServerにおけるクロスサイトスクリプティングの脆弱性 CWE-80
クロスサイトスクリプティング (Basic XSS)
CVE-2026-42030 2026-05-18 12:15 2026-05-8 Show GitHub Exploit DB Packet Storm
1194 6.5 警告
Network
argoproj Argo Workflows Argo Project AuthorsのArgo WorkflowsにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-42183 2026-05-18 12:14 2026-05-9 Show GitHub Exploit DB Packet Storm
1195 7.5 重要
Network
russh project
warpgate project
russh
warpgate
russh project等の複数ベンダの製品における複数の脆弱性 CWE-770
CWE-789
CVE-2026-42189 2026-05-18 12:14 2026-05-8 Show GitHub Exploit DB Packet Storm
1196 7.5 重要
Network
OWASP ModSecurity OWASPのModSecurityにおける複数の脆弱性 CWE-191
CWE-248
CVE-2026-42268 2026-05-18 12:14 2026-05-12 Show GitHub Exploit DB Packet Storm
1197 4.3 警告
Network
n8n-MCP n8n-MCP n8n-MCPにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-42282 2026-05-18 12:14 2026-05-8 Show GitHub Exploit DB Packet Storm
1198 7.5 重要
Network
argoproj Argo Workflows Argo Project AuthorsのArgo Workflowsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42294 2026-05-18 12:14 2026-05-9 Show GitHub Exploit DB Packet Storm
1199 4.4 警告
Local
Vim Vim VimにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-42307 2026-05-18 12:14 2026-05-8 Show GitHub Exploit DB Packet Storm
1200 7.8 重要
Local
Python Software Foundation Python Pillow Python Software FoundationのPython Pillowにおける複数の脆弱性 CWE-190
CWE-787
CVE-2026-42311 2026-05-18 12:14 2026-05-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318941 - - - An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. - CVE-2024-41264 2024-08-8 05:35 2024-08-2 Show GitHub Exploit DB Packet Storm
318942 - - - The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks - CVE-2024-2843 2024-08-8 05:35 2024-08-1 Show GitHub Exploit DB Packet Storm
318943 - abarcar abarcar_realty_portal Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to sl… CWE-89
SQL Injection
CVE-2006-5840 2024-08-8 05:15 2006-11-10 Show GitHub Exploit DB Packet Storm
318944 - marc_cagninacci mclinkscounter Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2)… CWE-94
Code Injection
CVE-2006-4863 2024-08-8 05:15 2006-09-20 Show GitHub Exploit DB Packet Storm
318945 - hitweb hitweb Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php,… NVD-CWE-Other
CVE-2006-4848 2024-08-8 05:15 2006-09-19 Show GitHub Exploit DB Packet Storm
318946 - phpopenchat phpopenchat PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter. NOTE: this issue was … NVD-CWE-Other
CVE-2006-4677 2024-08-8 05:15 2006-09-12 Show GitHub Exploit DB Packet Storm
318947 - linux linux_kernel The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local us… NVD-CWE-Other
CVE-2006-4663 2024-08-8 05:15 2006-09-9 Show GitHub Exploit DB Packet Storm
318948 - modulebased_cms modulebased_cms PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter in (1) admin/avatar.php, (2) libs/archive.class.ph… NVD-CWE-Other
CVE-2006-4545 2024-08-8 05:15 2006-09-6 Show GitHub Exploit DB Packet Storm
318949 - joomla
mambo
jim_component PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path paramete… NVD-CWE-Other
CVE-2006-4556 2024-08-8 05:15 2006-09-6 Show GitHub Exploit DB Packet Storm
318950 - phpprojekt phpprojekt Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitr… NVD-CWE-Other
CVE-2006-4609 2024-08-8 05:15 2006-09-7 Show GitHub Exploit DB Packet Storm