Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1311 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23757 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
1312 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23758 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
1313 6.5 警告
Network
Mattermost, Inc. Focalboard Mattermost, Inc.のFocalboardにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-25773 2026-04-30 12:13 2026-04-3 Show GitHub Exploit DB Packet Storm
1314 4.3 警告
Network
Mattermost, Inc. Focalboard Mattermost, Inc.のFocalboardにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-28736 2026-04-30 12:13 2026-04-3 Show GitHub Exploit DB Packet Storm
1315 7.8 重要
Local
DeepCool DeepCreative DeepCoolのDeepCreativeにおける安全でない継承されたパーミッションに関する脆弱性 CWE-277
安全でない継承されたパーミッション
CVE-2026-30266 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
1316 7.5 重要
Network
Angeet ES3 KVM Firmware AngeetのES3 KVM Firmwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-32297 2026-04-30 12:13 2026-03-17 Show GitHub Exploit DB Packet Storm
1317 9.1 緊急
Network
Angeet ES3 KVM Firmware AngeetのES3 KVM FirmwareにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-32298 2026-04-30 12:13 2026-03-17 Show GitHub Exploit DB Packet Storm
1318 7.5 重要
Network
オラクル Oracle Financial Services Customer Screening オラクルのOracle Financial Services Customer Screeningにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-34320 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
1319 5.8 警告
Network
Pavel Zbornik (pavelzbornik) whisperX REST API Pavel Zbornik (pavelzbornik)のwhisperX REST APIにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-34981 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
1320 7.5 重要
Network
Distribution Distribution Distributionにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-35172 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313401 - tor tor Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" sectio… NVD-CWE-Other
CVE-2006-3416 2024-08-8 04:15 2006-07-7 Show GitHub Exploit DB Packet Storm
313402 - jelsoft vbulletin Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this repor… NVD-CWE-Other
CVE-2006-3253 2024-08-8 04:15 2006-06-28 Show GitHub Exploit DB Packet Storm
313403 - microsoft windows_xp The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third pa… NVD-CWE-Other
CVE-2006-3209 2024-08-8 04:15 2006-06-24 Show GitHub Exploit DB Packet Storm
313404 - mysql
oracle
mysql Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local user… CWE-189
Numeric Errors
CVE-2006-3486 2024-08-8 04:15 2006-07-11 Show GitHub Exploit DB Packet Storm
313405 - mozilla firefox Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacke… NVD-CWE-Other
CVE-2006-3352 2024-08-8 04:15 2006-07-6 Show GitHub Exploit DB Packet Storm
313406 - phorum phorum SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report, st… NVD-CWE-Other
CVE-2006-3249 2024-08-8 04:15 2006-06-27 Show GitHub Exploit DB Packet Storm
313407 - nucleus_group nucleus_cms Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/n… CWE-94
Code Injection
CVE-2006-3136 2024-08-8 04:15 2006-06-23 Show GitHub Exploit DB Packet Storm
313408 - iglooweb doublespeak PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files… NVD-CWE-Other
CVE-2006-3069 2024-08-8 04:15 2006-06-19 Show GitHub Exploit DB Packet Storm
313409 - phorum phorum PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. NOTE: this issu… NVD-CWE-Other
CVE-2006-3053 2024-08-8 04:15 2006-06-16 Show GitHub Exploit DB Packet Storm
313410 - amr_talkbox amr_talkbox PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by C… NVD-CWE-Other
CVE-2006-3040 2024-08-8 04:15 2006-06-15 Show GitHub Exploit DB Packet Storm