Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1931 9.8 緊急
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-6771 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1932 7.5 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における例外的な状態のチェックに関する脆弱性 CWE-754
例外的な状態における不適切なチェック
CVE-2026-6772 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1933 7.5 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-6773 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1934 5.4 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-6774 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1935 5.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2026-6775 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1936 7.8 重要
Local
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2026-6776 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1937 5.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 CWE-20
CWE-352
CWE-400
CVE-2026-6777 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1938 5.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 CWE-476
CWE-824
CVE-2026-6778 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1939 5.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 CWE-119
CWE-20
CWE-79
CVE-2026-6779 2026-04-24 11:39 2026-04-21 Show GitHub Exploit DB Packet Storm
1940 7.5 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-6780 2026-04-24 11:38 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314421 7.5 HIGH
Network
broadcom bluecoat_security_gateway The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which all… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2004-2397 2024-02-14 01:17 2004-12-31 Show GitHub Exploit DB Packet Storm
314422 - myupb ultimate_php_board Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is execute… CWE-94
Code Injection
CVE-2003-0395 2024-02-14 01:14 2003-07-2 Show GitHub Exploit DB Packet Storm
314423 5.5 MEDIUM
Local
capturix scanshare Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2005-2209 2024-02-14 01:09 2005-07-11 Show GitHub Exploit DB Packet Storm
314424 - - - Rejected reason: **REJECT** Not a valid vulnerability. - CVE-2024-0707 2024-02-13 23:15 2024-02-13 Show GitHub Exploit DB Packet Storm
314425 - - - Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead. - CVE-2024-1420 2024-02-13 00:15 2024-02-13 Show GitHub Exploit DB Packet Storm
314426 7.5 HIGH
Network
phprank phprank phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2002-1800 2024-02-10 12:06 2002-12-31 Show GitHub Exploit DB Packet Storm
314427 7.5 HIGH
Network
audiogalaxy audiogalaxy Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2001-1536 2024-02-10 12:04 2001-12-31 Show GitHub Exploit DB Packet Storm
314428 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. All references and descriptions in this record have been removed to prevent accidental usage. - CVE-2023-6716 2024-02-9 18:15 2024-02-9 Show GitHub Exploit DB Packet Storm
314429 - georgecurrums open_guestbook Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter. CWE-79
Cross-site Scripting
CVE-2006-3295 2024-02-9 12:26 2006-06-29 Show GitHub Exploit DB Packet Storm
314430 - sun
oracle
jsse
java_web_start
jre
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 … CWE-295
Improper Certificate Validation 
CVE-2003-1229 2024-02-9 12:26 2003-12-31 Show GitHub Exploit DB Packet Storm