|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 25, 2026, 2:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1591 | 8.1 |
重要
Network |
Andreas Kloeckner | RELATE | Andreas KloecknerのRELATEにおける複数の脆弱性 |
CWE-203 CWE-208 |
CVE-2026-41588 | 2026-05-14 10:19 | 2026-05-8 | Show | GitHub Exploit DB Packet Storm |
| 1592 | 8.8 |
重要
Network |
NocoBase | NocoBase | NocoBaseにおけるSQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2026-41640 | 2026-05-14 10:19 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 1593 | 6.1 |
警告
Network |
fast-xml-parser project | fast-xml-parser | Natural Intelligenceのfast-xml-parserにおけるブラインド XPath インジェクションの脆弱性 |
CWE-91
ブラインド XPath インジェクション |
CVE-2026-41650 | 2026-05-14 10:18 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 1594 | 4.4 |
警告
Local |
Anthropic PBC | Claude SDK for TypeScript (anthropic-ai/sdk) | Anthropic PBCのClaude SDK for TypeScript (anthropic-ai/sdk)における重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 |
CWE-732
重要なリソースに対する不適切なパーミッションの割り当て |
CVE-2026-41686 | 2026-05-14 10:18 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
| 1595 | 8.6 |
重要
Network |
VMware | Spring AI | VMwareのSpring AIにおける言語構文の表現に使用される特殊な要素の不適切な無効化に関する脆弱性 |
CWE-917
言語構文の表現に使用される特殊な要素の不適切な無効化 |
CVE-2026-41705 | 2026-05-14 10:18 | 2026-05-9 | Show | GitHub Exploit DB Packet Storm |
| 1596 | 7.5 |
重要
Network |
VMware | Spring AI | VMwareのSpring AIにおける不適切なデフォルトパーミッションに関する脆弱性 |
CWE-276
不適切なデフォルトパーミッション |
CVE-2026-41712 | 2026-05-14 10:18 | 2026-05-12 | Show | GitHub Exploit DB Packet Storm |
| 1597 | 8.2 |
重要
Network |
VMware | Spring AI | VMwareのSpring AIにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 |
CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化 |
CVE-2026-41713 | 2026-05-14 10:18 | 2026-05-12 | Show | GitHub Exploit DB Packet Storm |
| 1598 | 6.5 |
警告
Network |
LangGenius | Dify | LangGeniusのDifyにおけるユーザ制御の鍵による認証回避に関する脆弱性 |
CWE-639
ユーザ制御の鍵による認証回避 |
CVE-2026-41950 | 2026-05-14 10:18 | 2026-05-5 | Show | GitHub Exploit DB Packet Storm |
| 1599 | 9.6 |
緊急
Network |
Streetwriters |
Notesnook Mobile Notesnook Desktop |
StreetwritersのNotesnook Desktop等の複数製品における複数の脆弱性 |
CWE-79 CWE-94 |
CVE-2026-42090 | 2026-05-14 10:18 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
| 1600 | 6.5 |
警告
Network |
goshs | goshs | goshsにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2026-42091 | 2026-05-14 10:18 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 25, 2026, 4:01 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 346171 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, w… |
NVD-CWE-Other
|
CVE-2004-1084 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346172 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode. |
NVD-CWE-Other
|
CVE-2004-1085 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346173 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file. |
NVD-CWE-Other
|
CVE-2004-1086 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346174 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user. |
NVD-CWE-Other
|
CVE-2004-1087 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346175 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information. |
NVD-CWE-Other
|
CVE-2004-1088 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346176 | - | apple |
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server |
Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users. |
NVD-CWE-Other
|
CVE-2004-1089 | 2017-07-11 10:30 | 2004-12-2 | Show | GitHub Exploit DB Packet Storm | |
| 346177 | - |
midnight_commander debian gentoo redhat suse turbolinux |
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation |
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." |
NVD-CWE-Other
|
CVE-2004-1090 | 2017-07-11 10:30 | 2005-04-14 | Show | GitHub Exploit DB Packet Storm | |
| 346178 | - |
midnight_commander debian gentoo redhat suse turbolinux |
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation |
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference. |
NVD-CWE-Other
|
CVE-2004-1091 | 2017-07-11 10:30 | 2005-04-14 | Show | GitHub Exploit DB Packet Storm | |
| 346179 | - |
midnight_commander debian gentoo redhat suse turbolinux |
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation |
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. |
NVD-CWE-Other
|
CVE-2004-1092 | 2017-07-11 10:30 | 2005-04-14 | Show | GitHub Exploit DB Packet Storm | |
| 346180 | - |
midnight_commander debian gentoo redhat suse turbolinux |
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation |
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." |
NVD-CWE-Other
|
CVE-2004-1093 | 2017-07-11 10:30 | 2005-04-14 | Show | GitHub Exploit DB Packet Storm |