Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2361 7.2 重要
Network
JetBrains YouTrack JetBrainsのYouTrackにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-33392 2026-04-21 10:49 2026-04-17 Show GitHub Exploit DB Packet Storm
2362 6.3 警告
Network
Check MK Check MK Check MKにおける区切り文字の不適切な無害化に関する脆弱性 CWE-140
区切り文字の不適切な無害化
CVE-2026-33455 2026-04-21 10:49 2026-04-10 Show GitHub Exploit DB Packet Storm
2363 7.6 重要
Network
Check MK Check MK Check MKにおける区切り文字の不適切な無害化に関する脆弱性 CWE-140
区切り文字の不適切な無害化
CVE-2026-33456 2026-04-21 10:49 2026-04-10 Show GitHub Exploit DB Packet Storm
2364 6.3 警告
Network
Check MK Check MK Check MKにおける区切り文字の不適切な無害化に関する脆弱性 CWE-140
区切り文字の不適切な無害化
CVE-2026-33457 2026-04-21 10:48 2026-04-10 Show GitHub Exploit DB Packet Storm
2365 7.5 重要
Network
goxmldsig project goxmldsig goxmldsig projectのgoxmldsigにおける複数の脆弱性 CWE-347
CWE-682
CVE-2026-33487 2026-04-21 10:48 2026-03-26 Show GitHub Exploit DB Packet Storm
2366 8.7 重要
Local
Craig J. Bass (craigjbass) ClearanceKit Craig J. Bass (craigjbass)のClearanceKitにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33631 2026-04-21 10:48 2026-03-26 Show GitHub Exploit DB Packet Storm
2367 7.5 重要
Network
Moby Project buildkit Moby Projectのbuildkitにおける複数の脆弱性 CWE-22
CWE-59
CVE-2026-33748 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
2368 8.8 重要
Network
Intermesh Group-Office Intermesh BVのGroup-OfficeにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-33755 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
2369 7.5 重要
Network
saleor saleor saleorにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-33756 2026-04-21 10:48 2026-04-8 Show GitHub Exploit DB Packet Storm
2370 3.7
Network
Apostrophe Technologies ApostropheCMS Apostrophe TechnologiesのApostropheCMSにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-33877 2026-04-21 10:48 2026-04-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348501 - dream4 koobi_cms SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter. NVD-CWE-Other
CVE-2005-0890 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348502 - instance_four
sacred
ubi_soft
tincat
sacred
the_settlersheritage_of_kings
Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute a… NVD-CWE-Other
CVE-2005-0906 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348503 - valdersoft shopping_cart Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.… NVD-CWE-Other
CVE-2005-0907 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348504 - valdersoft valdersoft_shopping_cart Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the se… NVD-CWE-Other
CVE-2005-0908 2008-09-6 05:47 2005-03-28 Show GitHub Exploit DB Packet Storm
348505 - e-xoops e-xoops Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat paramete… NVD-CWE-Other
CVE-2005-0910 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348506 - e-xoops e-xoops Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle … NVD-CWE-Other
CVE-2005-0911 2008-09-6 05:47 2005-03-28 Show GitHub Exploit DB Packet Storm
348507 - deplate deplate Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb. NVD-CWE-Other
CVE-2005-0912 2008-09-6 05:47 2005-03-24 Show GitHub Exploit DB Packet Storm
348508 - cpg-nuke cpg_dragonfly_cms Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat pa… NVD-CWE-Other
CVE-2005-0914 2008-09-6 05:47 2005-03-26 Show GitHub Exploit DB Packet Storm
348509 - webmasters-debutants wd_guestbook Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.ph… NVD-CWE-Other
CVE-2005-0915 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348510 - linux linux_kernel AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_qu… NVD-CWE-Other
CVE-2005-0916 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm