Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2311 3.6
Local
ARM Ltd. Arm C1-Pro ファームウェア ARM Ltd.のArm C1-Pro ファームウェアにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-0995 2026-04-21 10:51 2026-03-2 Show GitHub Exploit DB Packet Storm
2312 8.1 重要
Network
Grafana Labs Grafana Grafana LabsのGrafanaにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-21721 2026-04-21 10:51 2026-01-27 Show GitHub Exploit DB Packet Storm
2313 5.3 警告
Network
Grafana Labs Loki Grafana LabsのLokiにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-21726 2026-04-21 10:51 2026-04-15 Show GitHub Exploit DB Packet Storm
2314 3.3
Network
Grafana Labs Grafana Grafana LabsのGrafanaにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2026-21727 2026-04-21 10:51 2026-04-15 Show GitHub Exploit DB Packet Storm
2315 4.8 警告
Network
フォーティネット FortiNAC-F フォーティネットのFortiNAC-Fにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-21741 2026-04-21 10:51 2026-04-14 Show GitHub Exploit DB Packet Storm
2316 8.8 重要
Network
AFFiNE AFFiNE AFFiNEにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-21853 2026-04-21 10:51 2026-03-2 Show GitHub Exploit DB Packet Storm
2317 5.7 警告
Network
デル data domain operating system デルのdata domain operating systemにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-23775 2026-04-21 10:51 2026-04-17 Show GitHub Exploit DB Packet Storm
2318 5.3 警告
Network
PowerDNS PowerDNS Recursor PowerDNSのPowerDNS RecursorにおけるCapture-replay による認証回避に関する脆弱性 CWE-294
Capture-replayによる認証回避
CVE-2026-24027 2026-04-21 10:51 2026-02-9 Show GitHub Exploit DB Packet Storm
2319 6.7 警告
Local
Acronis International GmbH True Image Acronis International GmbHのTrue Imageにおける制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2026-27774 2026-04-21 10:51 2026-04-2 Show GitHub Exploit DB Packet Storm
2320 5.3 警告
Network
Talishar Talishar Talisharにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-28428 2026-04-21 10:51 2026-03-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314821 9.8 CRITICAL
Network
openbsd openssh Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is usin… CWE-190
 Integer Overflow or Wraparound
CVE-2002-0639 2024-02-9 03:37 2002-07-3 Show GitHub Exploit DB Packet Storm
314822 7.8 HIGH
Local
linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which cau… CWE-190
 Integer Overflow or Wraparound
CVE-2004-2013 2024-02-9 02:59 2004-12-31 Show GitHub Exploit DB Packet Storm
314823 9.8 CRITICAL
Network
wuftpd
redhat
apple
sun
freebsd
netbsd
openbsd
wu-ftpd
wu_ftpd
mac_os_x_server
mac_os_x
solaris
freebsd
netbsd
openbsd
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via command… CWE-193
 Off-by-one Error
CVE-2003-0466 2024-02-9 00:50 2003-08-27 Show GitHub Exploit DB Packet Storm
314824 5.5 MEDIUM
Local
mandrakesoft mandrake_linux The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files. CWE-276
Incorrect Default Permissions 
CVE-2002-1713 2024-02-9 00:50 2002-12-31 Show GitHub Exploit DB Packet Storm
314825 7.8 HIGH
Local
microsoft windows_media_player Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privile… CWE-276
Incorrect Default Permissions 
CVE-2002-1844 2024-02-9 00:50 2002-12-31 Show GitHub Exploit DB Packet Storm
314826 9.8 CRITICAL
Network
suse suse_linux The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. CWE-276
Incorrect Default Permissions 
CVE-1999-0426 2024-02-9 00:50 1999-03-1 Show GitHub Exploit DB Packet Storm
314827 7.8 HIGH
Local
isc bind dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which al… CWE-276
Incorrect Default Permissions 
CVE-2001-0497 2024-02-9 00:49 2001-07-21 Show GitHub Exploit DB Packet Storm
314828 7.5 HIGH
Network
aol aim The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer under… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2005-1891 2024-02-9 00:44 2005-06-9 Show GitHub Exploit DB Packet Storm
314829 9.8 CRITICAL
Network
barton ngircd Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2005-0199 2024-02-9 00:43 2005-05-2 Show GitHub Exploit DB Packet Storm
314830 7.5 HIGH
Network
samba
canonical
ppp
ubuntu_linux
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an inco… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2004-1002 2024-02-9 00:43 2005-03-1 Show GitHub Exploit DB Packet Storm