Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1601 6.7 警告
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows リッチ テキスト エディットの特権昇格の脆弱性 CWE-415
二重解放
CVE-2026-32170 2026-05-18 12:18 2026-05-12 Show GitHub Exploit DB Packet Storm
1602 4.4 警告
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows フィルタリング プラットフォーム (WFP) のセキュリティ機能のバイパスの脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-32209 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1603 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows Event Logging Service の特権の昇格の脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-33834 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1604 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Wind…
Windows Cloud Files Mini Filter ドライバーの特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33835 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1605 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows TCP/IP Local の特権昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-33837 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1606 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows メッセージ キュー (MSMQ) の特権昇格の脆弱性 CWE-415
二重解放
CVE-2026-33838 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1607 7 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Wind…
Win32k の特権の昇格の脆弱性 CWE-362
競合状態
CVE-2026-33839 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1608 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Win32k の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33840 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1609 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows 11 24h2
Microsoft Wind…
Windows カーネルの特権の昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-33841 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1610 7.5 重要
Network
MediaWiki MediaWiki MediaWikiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-34087 2026-05-18 12:17 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345291 - djayp phpmysport Directory traversal vulnerability in index.php in phpMySport 1.4 allows remote attackers to list arbitrary directories via a .. (dot dot) in the current_folder parameter. CWE-22
Path Traversal
CVE-2010-1110 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345292 - easysitenetwork jokes_complete_website Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and the (2) searchingr… CWE-79
Cross-site Scripting
CVE-2010-1111 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345293 - comscripts web_server_creator_web_portal Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php. CWE-79
Cross-site Scripting
CVE-2010-1113 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345294 - comscripts web_server_creator_web_portal Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (… CWE-94
Code Injection
CVE-2010-1114 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345295 - comscripts web_server_creator_web_portal Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter. CWE-22
Path Traversal
CVE-2010-1115 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345296 - aspindir lookmer_muzik_portal LookMer Music Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for dbmdb/LookMerSarki… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1116 2017-08-17 10:32 2010-03-26 Show GitHub Exploit DB Packet Storm
345297 - georg_greve spamassassin_milter_plugin The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacter… CWE-78
OS Command 
CVE-2010-1132 2017-08-17 10:32 2010-03-28 Show GitHub Exploit DB Packet Storm
345298 - tiki tikiwiki_cms\/groupware Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchin… CWE-89
SQL Injection
CVE-2010-1133 2017-08-17 10:32 2010-03-28 Show GitHub Exploit DB Packet Storm
345299 - tiki tikiwiki_cms\/groupware SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable. CWE-89
SQL Injection
CVE-2010-1134 2017-08-17 10:32 2010-03-28 Show GitHub Exploit DB Packet Storm
345300 - tiki tikiwiki_cms\/groupware The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse. CWE-255
Credentials Management
CVE-2010-1135 2017-08-17 10:32 2010-03-28 Show GitHub Exploit DB Packet Storm