Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1901 6.7 警告
Local
Acronis International GmbH True Image Acronis International GmbHのTrue Imageにおける制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2026-28728 2026-04-21 10:50 2026-04-2 Show GitHub Exploit DB Packet Storm
1902 8.3 重要
Network
Daylight Studio FUEL CMS Daylight StudioのFUEL CMSにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-30461 2026-04-21 10:50 2026-04-15 Show GitHub Exploit DB Packet Storm
1903 8.6 重要
Network
Agent Zero Agent Zero Agent Zeroにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-30624 2026-04-21 10:50 2026-04-15 Show GitHub Exploit DB Packet Storm
1904 7.5 重要
Network
Apache Software Foundation skywalking Apache Software Foundationのskywalkingにおけるデータクエリからの重要な情報の漏えいに関する脆弱性 CWE-202
データクエリからの重要な情報の漏えい
CVE-2026-30778 2026-04-21 10:50 2026-04-15 Show GitHub Exploit DB Packet Storm
1905 7.5 重要
Network
Apache Software Foundation Apache Airflow Apache Software FoundationのApache Airflowにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-31987 2026-04-21 10:50 2026-04-16 Show GitHub Exploit DB Packet Storm
1906 4.8 警告
Network
OpenClaw OpenClaw OpenClawにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-32018 2026-04-21 10:50 2026-03-19 Show GitHub Exploit DB Packet Storm
1907 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-32019 2026-04-21 10:50 2026-03-19 Show GitHub Exploit DB Packet Storm
1908 7.1 重要
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-32035 2026-04-21 10:50 2026-03-19 Show GitHub Exploit DB Packet Storm
1909 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows Function Discovery Service (fdwsd.dll) の特権昇格の脆弱性 CWE-122
CWE-362
CWE-367
CVE-2026-32093 2026-04-21 10:50 2026-04-14 Show GitHub Exploit DB Packet Storm
1910 7.3 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows Hyper-V のリモートでコードが実行される脆弱性 CWE-122
CWE-191
CWE-20
CVE-2026-32149 2026-04-21 10:50 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349421 - leszek_krupinski l-forum L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which… NVD-CWE-Other
CVE-2002-1460 2008-09-6 05:30 2003-06-9 Show GitHub Exploit DB Packet Storm
349422 - webscriptworld web_shop_manager Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box. NVD-CWE-Other
CVE-2002-1461 2008-09-6 05:30 2003-06-9 Show GitHub Exploit DB Packet Storm
349423 - organicphp php-affiliate details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields. NVD-CWE-Other
CVE-2002-1462 2008-09-6 05:30 2003-06-9 Show GitHub Exploit DB Packet Storm
349424 - cafelog b2 Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable. NVD-CWE-Other
CVE-2002-1464 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349425 - cafelog b2 SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. NVD-CWE-Other
CVE-2002-1465 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349426 - cafelog b2 CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. NVD-CWE-Other
CVE-2002-1466 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349427 - macromedia flash_player
shockwave
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3)… NVD-CWE-Other
CVE-2002-1467 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349428 - ibm aix Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root. NVD-CWE-Other
CVE-2002-1468 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349429 - scponly scponly scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs … NVD-CWE-Other
CVE-2002-1469 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm
349430 - nullsoft shoutcast_server SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log… NVD-CWE-Other
CVE-2002-1470 2008-09-6 05:30 2003-04-22 Show GitHub Exploit DB Packet Storm