Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1421 7.5 重要
Network
Getarcane Arcane GetarcaneのArcaneにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-42461 2026-05-18 11:30 2026-05-9 Show GitHub Exploit DB Packet Storm
1422 8.1 重要
Network
FIT2CLOUD SQLBot FIT2CLOUDのSQLBotにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-42463 2026-05-18 11:30 2026-05-13 Show GitHub Exploit DB Packet Storm
1423 7.8 重要
Local
マイクロソフト Microsoft Office マイクロソフトのMicrosoft Officeにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-42831 2026-05-18 11:30 2026-05-12 Show GitHub Exploit DB Packet Storm
1424 5.5 警告
Local
マイクロソフト Microsoft Word
Microsoft Office
Microsoft Excel
マイクロソフトのMicrosoft Excel等の複数製品におけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-42832 2026-05-18 11:30 2026-05-12 Show GitHub Exploit DB Packet Storm
1425 7.5 重要
Network
Espressif Systems ESP32 Arduino Espressif SystemsのESP32 Arduinoにおける認証に関する脆弱性 CWE-287
CWE-noinfo
CVE-2026-42855 2026-05-18 11:30 2026-05-12 Show GitHub Exploit DB Packet Storm
1426 6.1 警告
Network
マイクロソフト Microsoft Exchange Server マイクロソフトのMicrosoft Exchange Serverにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42897 2026-05-18 11:30 2026-05-14 Show GitHub Exploit DB Packet Storm
1427 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-43286 2026-05-18 11:29 2026-05-8 Show GitHub Exploit DB Packet Storm
1428 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-43287 2026-05-18 11:29 2026-05-8 Show GitHub Exploit DB Packet Storm
1429 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける初期化されていないリソースの使用に関する脆弱性 CWE-908
初期化されていないリソースの使用
CVE-2026-43288 2026-05-18 11:29 2026-05-8 Show GitHub Exploit DB Packet Storm
1430 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43289 2026-05-18 11:29 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345761 - jason_geiger zoph SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands. NVD-CWE-Other
CVE-2006-0402 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345762 - mike_macgirvin note-a-day_weblog Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive… NVD-CWE-Other
CVE-2006-0404 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345763 - libtiff libtiff The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer derefe… NVD-CWE-Other
CVE-2006-0405 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345764 - libtiff libtiff Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference' NVD-CWE-Other
CVE-2006-0405 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345765 - sun grid_engine rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments. NVD-CWE-Other
CVE-2006-0408 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345766 - john_lim adodb SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings. NVD-CWE-Other
CVE-2006-0410 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345767 - claroline claroline claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges. NVD-CWE-Other
CVE-2006-0411 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345768 - gencbeyin_web_programlama cybershop SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. CWE-89
SQL Injection
CVE-2006-0412 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345769 - tor tor Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to… NVD-CWE-Other
CVE-2006-0414 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm
345770 - sleeperchat sleeperchat Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter. NVD-CWE-Other
CVE-2006-0415 2017-07-20 10:29 2006-01-25 Show GitHub Exploit DB Packet Storm