Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229511 5 警告 webasyst llc - Shop-Script の premium/index.php における CRLF インジェクションの脆弱性 - CVE-2006-5566 2012-12-20 18:02 2006-10-27 Show GitHub Exploit DB Packet Storm
229512 5 警告 Yahoo! - Yahoo! Messenger におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5563 2012-12-20 18:02 2006-10-27 Show GitHub Exploit DB Packet Storm
229513 7.5 危険 revilloc solutions - RevilloC MailServer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-5552 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229514 7.5 危険 qksoft - QK SMTP におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-5551 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229515 5 警告 シマンテック - Domino Server 用の Symantec Mail Security におけるスパム送信用の踏み台として製品を使用される脆弱性 - CVE-2006-5545 2012-12-20 18:02 2006-10-19 Show GitHub Exploit DB Packet Storm
229516 7.5 危険 ueberproject management system - UeberProject Management System の login/secure.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5539 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229517 4.3 警告 zwahlen informatik - Zwahlen Online Shop Freeware の index.htm におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-5534 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229518 6.8 警告 XOOPS - RMSOFT Gallery System の rmgs/images.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5532 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229519 5.1 警告 schoolalumni portal - SchoolAlumni Portal の smumdadotcom_ascyb_alumni/mod.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5529 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229520 5 警告 schoolalumni portal - SchoolAlumni Portal の mod.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5528 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
541 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security… New CWE-307
CWE-362
CWE-367
mproper Restriction of Excessive Authentication Attempts
Race Condition
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-26206 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
542 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() i… New CWE-121
CWE-400
Stack-based Buffer Overflow
 Uncontrolled Resource Consumption
CVE-2026-28221 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
543 9.0 CRITICAL
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchroniz… New CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-30893 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
544 9.8 CRITICAL
Network
- - Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send… New CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25316 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
545 9.8 CRITICAL
Network
- - Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se… New CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25317 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
546 9.8 CRITICAL
Network
- - Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca… New CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25318 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
547 5.5 MEDIUM
Local
- - ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service New CWE-674
 Uncontrolled Recursion
CVE-2026-5299 2026-05-1 00:10 2026-04-30 Show GitHub Exploit DB Packet Storm
548 5.5 MEDIUM
Local
- - AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service New CWE-674
 Uncontrolled Recursion
CVE-2026-5401 2026-05-1 00:10 2026-04-30 Show GitHub Exploit DB Packet Storm
549 5.5 MEDIUM
Local
- - FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service New CWE-674
 Uncontrolled Recursion
CVE-2026-5406 2026-05-1 00:10 2026-04-30 Show GitHub Exploit DB Packet Storm
550 5.5 MEDIUM
Local
- - SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service New CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-5407 2026-05-1 00:10 2026-04-30 Show GitHub Exploit DB Packet Storm