Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
121 9.1 緊急
Network
マイクロソフト ASP.NET Core ASP.NET Core Elevation of Privilege Vulnerability New CWE-347
デジタル署名の不適切な検証
CVE-2026-40372 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
122 5.4 警告
Network
Kimai project kimai Kimai projectのKimaiにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40479 2026-04-30 12:28 2026-04-17 Show GitHub Exploit DB Packet Storm
123 4.3 警告
Network
Kimai project kimai Kimai projectのKimaiにおける動的に決定されたオブジェクト属性の不適切に制御された変更に関する脆弱性 New CWE-915
動的に決定されたオブジェクト属性の不適切に制御された変更
CVE-2026-40486 2026-04-30 12:28 2026-04-17 Show GitHub Exploit DB Packet Storm
124 6.8 警告
Network
oauth2_proxy project oauth2_proxy oauth2_proxy projectのoauth2_proxyにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-40574 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
125 9.1 緊急
Network
oauth2_proxy project oauth2_proxy oauth2_proxy projectのoauth2_proxyにおけるスプーフィングによる認証回避に関する脆弱性 New CWE-290
スプーフィングによる認証回避
CVE-2026-40575 2026-04-30 12:28 2026-04-22 Show GitHub Exploit DB Packet Storm
126 4.8 警告
Network
pyLoad-ng project pyLoad-ng pyLoad-ng projectのpyLoad-ngにおける同一生成元ポリシー違反に関する脆弱性 New CWE-346
同一生成元ポリシー違反
CVE-2026-40594 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
127 8.1 重要
Network
The Kyverno Authors Kyverno The Kyverno AuthorsのKyvernoにおける重要な情報のセキュアでない格納に関する脆弱性 New CWE-922
重要な情報のセキュアでない格納
CVE-2026-40868 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
128 8.1 重要
Network
goshs goshs goshsにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-40883 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
129 9.8 緊急
Network
goshs goshs goshsにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-40884 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
130 8.8 重要
Network
goshs goshs goshsにおける情報漏えいに関する脆弱性 New CWE-200
CWE-noinfo
CVE-2026-40885 2026-04-30 12:28 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313681 - microsoft internet_explorer
windows_2003_server
windows_server_2003
windows_xp
windows_server_2008
windows_vista
windows_7
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly ini… CWE-94
Code Injection
CVE-2010-0490 2023-12-8 03:38 2010-04-1 Show GitHub Exploit DB Packet Storm
313682 - microsoft internet_explorer
windows_2003_server
windows_server_2003
windows_xp
windows_server_2008
windows_vista
windows_2000
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condit… CWE-362
Race Condition
CVE-2010-0489 2023-12-8 03:38 2010-04-1 Show GitHub Exploit DB Packet Storm
313683 - microsoft internet_explorer
windows_2003_server
windows_server_2003
windows_xp
windows_server_2008
windows_vista
windows_2000
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive info… CWE-200
Information Exposure
CVE-2010-0488 2023-12-8 03:38 2010-04-1 Show GitHub Exploit DB Packet Storm
313684 - microsoft internet_explorer
windows_2003_server
windows_server_2003
windows_xp
windows_server_2008
windows_vista
windows_2000
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initia… CWE-94
Code Injection
CVE-2010-0267 2023-12-8 03:38 2010-04-1 Show GitHub Exploit DB Packet Storm
313685 - microsoft internet_explorer
windows_2003_server
windows_server_2003
windows_xp
windows_server_2008
windows_vista
windows_2000
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving acc… CWE-399
 Resource Management Errors
CVE-2010-0806 2023-12-8 03:38 2010-03-11 Show GitHub Exploit DB Packet Storm
313686 - microsoft windows_movie_maker
windows_xp
windows_vista
producer
Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Make… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-0265 2023-12-8 03:38 2010-03-11 Show GitHub Exploit DB Packet Storm
313687 - microsoft windows_2000
windows_xp
windows_2003_server
windows_vista
windows_server_2008
windows_7
The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2,… CWE-94
Code Injection
CVE-2010-0252 2023-12-8 03:38 2010-02-11 Show GitHub Exploit DB Packet Storm
313688 - microsoft windows_xp
windows_server_2008
windows_7
windows_vista
Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, W… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-0250 2023-12-8 03:38 2010-02-11 Show GitHub Exploit DB Packet Storm
313689 - microsoft windows_server_2008
windows_vista
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malfor… CWE-399
 Resource Management Errors
CVE-2010-0242 2023-12-8 03:38 2010-02-11 Show GitHub Exploit DB Packet Storm
313690 - microsoft windows_server_2008
windows_vista
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packe… CWE-94
Code Injection
CVE-2010-0241 2023-12-8 03:38 2010-02-11 Show GitHub Exploit DB Packet Storm