Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232261 9.3 危険 sandh - S&H Computer Systems News Rover におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-1041 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232262 7.5 危険 xpression news - X-News の archives.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1040 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232263 5 警告 shemes.com - Shemes.com Grabit におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1038 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232264 9.3 危険 rsbr-software - News File Grabber におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-1037 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232265 7.5 危険 PHPNUKE - PHP-Nuke 用の Emporium モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1034 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232266 6.8 警告 phpMyFAQ - phpMyFAQ における "サーバ上にファイルをアップロードする権限を取得される" 脆弱性 CWE-noinfo
情報不足
CVE-2007-1032 2012-12-20 18:19 2007-02-8 Show GitHub Exploit DB Packet Storm
232267 6.8 警告 spoonlabs - SpoonLabs Vivvo Article Management CMS の include/db_conn.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-1031 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232268 7.6 危険 quicksoft - Quiksoft EasyMail Objects の IMAP4 コンポーネントにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1029 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232269 7.5 危険 scriptdungeon - XLAtunes の view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1026 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
232270 7.5 危険 virtualsystem - VS-Link-Partner の inc/functions_inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1025 2012-12-20 18:19 2007-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
621 - - - A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. New CWE-36
 Absolute Path Traversal
CVE-2026-32997 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
622 - - - This vulnerability in Veeam Service Provider Console allows for remote code execution. New CWE-233
 Improper Handling of Parameters
CVE-2026-32998 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
623 9.0 CRITICAL
Network
- - Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the aff… New CWE-94
Code Injection
CVE-2026-32999 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
624 - - - Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precise… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-9828 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
625 - - - When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embe… New CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-6720 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm
626 6.5 MEDIUM
Network
- - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect… New CWE-706
 Use of Incorrectly-Resolved Name or Reference
CVE-2026-45306 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm
627 5.0 MEDIUM
Network
- - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-46561 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm
628 8.7 HIGH
Network
- - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates … New CWE-79
Cross-site Scripting
CVE-2026-45348 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm
629 8.8 HIGH
Network
- - vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and … New CWE-22
Path Traversal
CVE-2026-4944 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm
630 - - - In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names e… New CWE-863
 Incorrect Authorization
CVE-2026-49299 2026-05-30 00:39 2026-05-29 Show GitHub Exploit DB Packet Storm