Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2301 8.8 重要
Network
FIT2CLOUD SQLBot FIT2CLOUDのSQLBotにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-33324 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
2302 5.3 警告
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33420 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
2303 7.5 重要
Network
coredns.io CoreDNS The CoreDNS AuthorsのCoreDNSにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-33489 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
2304 6.5 警告
Network
マイクロソフト Microsoft Teams Microsoft Team Events Portal Information Disclosure Vulnerability CWE-285
不適切な認可
CVE-2026-33823 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
2305 9 緊急
Network
マイクロソフト Azure Managed Instance for Apache Cassandra Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability CWE-20
不適切な入力確認
CVE-2026-33844 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
2306 8.2 重要
Network
マイクロソフト Microsoft Partner Center Microsoft Partner Center Spoofing Vulnerability CWE-610
別領域リソースに対する外部からの制御可能な参照
CVE-2026-34327 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
2307 5.3 警告
Network
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける弱いハッシュの使用に関する脆弱性 CWE-328
脆弱なハッシュの使用
CVE-2026-34527 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
2308 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35072 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
2309 6.7 警告
Local
デル data domain operating system デルのdata domain operating systemにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35073 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
2310 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35074 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
354381 - yabb yabb Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action. NVD-CWE-Other
CVE-2005-0741 2008-09-6 05:47 2005-03-8 Show GitHub Exploit DB Packet Storm
354382 - utstarcom ian-02ex_voip_ata UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset. NVD-CWE-Other
CVE-2005-0745 2008-09-6 05:47 2005-03-9 Show GitHub Exploit DB Packet Storm
354383 - applyyourself i-class ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.… NVD-CWE-Other
CVE-2005-0747 2008-09-6 05:47 2005-03-8 Show GitHub Exploit DB Packet Storm
354384 - midnight_commander midnight_commander Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code. NVD-CWE-Other
CVE-2005-0763 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354385 - marc_lehmann rxvt-unicode Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences. NVD-CWE-Other
CVE-2005-0764 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354386 - notify_technology notifylink NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to pr… NVD-CWE-Other
CVE-2005-0809 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354387 - notify_technology notifylink SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL. NVD-CWE-Other
CVE-2005-0810 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354388 - notify_technology notifylink The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a di… NVD-CWE-Other
CVE-2005-0811 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354389 - notify_technology notifylink The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information. NVD-CWE-Other
CVE-2005-0812 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
354390 - initial_redirect initial_redirect_squid_proxy_plug-in Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors. NVD-CWE-Other
CVE-2005-0813 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm