Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
161 7.5 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-44573 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
162 8.1 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 New CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-44574 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
163 7.5 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 New CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-44575 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
164 5.9 警告
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-44577 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
165 10 緊急
Network
Peerigon angular-expressions Peerigonのangular-expressionsにおけるEval インジェクションに関する脆弱性 New CWE-95
Evalインジェクション
CVE-2026-44643 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
166 7.7 重要
Network
Grav CMS grav Grav CMSのgravにおける情報漏えいに関する脆弱性 New CWE-200
CWE-noinfo
CVE-2026-44738 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
167 5.5 警告
Local
jqlang jq jqlangのjqにおける再帰制御に関する脆弱性 New CWE-674
不適切な再帰制御
CVE-2026-44777 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
168 4.2 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-44991 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
169 5 警告
Local
OpenClaw OpenClaw OpenClawにおけるフィルタリングの回避に関する脆弱性 New CWE-441
フィルタリング回避
CVE-2026-44992 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
170 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける不完全なブラックリストに関する脆弱性 New CWE-184
不完全なブラックリスト
CVE-2026-44993 2026-05-15 10:57 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346481 - hosting_controller hosting_controller The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domai… NVD-CWE-Other
CVE-2005-0695 2016-10-18 12:13 2005-03-7 Show GitHub Exploit DB Packet Storm
346482 - oracle database_server Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE funct… NVD-CWE-Other
CVE-2005-0701 2016-10-18 12:13 2005-03-7 Show GitHub Exploit DB Packet Storm
346483 - gamearena experience2 PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server t… NVD-CWE-Other
CVE-2005-0721 2016-10-18 12:13 2005-05-2 Show GitHub Exploit DB Packet Storm
346484 - seth_m._knorr biz_mail_form CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email … NVD-CWE-Other
CVE-2005-0493 2016-10-18 12:12 2005-05-2 Show GitHub Exploit DB Packet Storm
346485 - seth_m._knorr biz_mail_form Upgrade to newest version. NVD-CWE-Other
CVE-2005-0493 2016-10-18 12:12 2005-05-2 Show GitHub Exploit DB Packet Storm
346486 - avaya ip_office_phone_manager
ip_soft_phone
The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames a… NVD-CWE-Other
CVE-2005-0506 2016-10-18 12:12 2005-03-14 Show GitHub Exploit DB Packet Storm
346487 - gd_software sd_server Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request. NVD-CWE-Other
CVE-2005-0507 2016-10-18 12:12 2005-03-14 Show GitHub Exploit DB Packet Storm
346488 - microsoft
mono
.net_framework
mono
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for AS… NVD-CWE-Other
CVE-2005-0509 2016-10-18 12:12 2005-03-14 Show GitHub Exploit DB Packet Storm
346489 - jelsoft vbulletin misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter. NVD-CWE-Other
CVE-2005-0511 2016-10-18 12:12 2005-02-21 Show GitHub Exploit DB Packet Storm
346490 - pmachine pmachine_pro PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to exec… NVD-CWE-Other
CVE-2005-0513 2016-10-18 12:12 2005-02-19 Show GitHub Exploit DB Packet Storm