Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2431 6.2 警告
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Active Directory のなりすましの脆弱性 CWE-287
不適切な認証
CVE-2026-32072 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
2432 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32073 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
2433 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows Projected File System の特権の昇格の脆弱性 CWE-415
二重解放
CVE-2026-32074 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
2434 7.5 重要
Network
EMQX nanomq EMQXのnanomqにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-32135 2026-04-24 11:31 2026-04-20 Show GitHub Exploit DB Packet Storm
2435 7.4 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP デバイス ホストのリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32156 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
2436 7.5 重要
Network
jqlang jq jqlangのjqにおける複数の脆弱性 CWE-122
CWE-190
CVE-2026-32316 2026-04-24 11:31 2026-04-13 Show GitHub Exploit DB Packet Storm
2437 8.1 重要
Network
nginxui nginx ui Nginx UI TeamのNginx UIにおける複数の脆弱性 CWE-284
CWE-863
CVE-2026-33031 2026-04-24 11:31 2026-04-20 Show GitHub Exploit DB Packet Storm
2438 4.3 警告
Network
Docmost Docmost Docmostにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-33146 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
2439 8.1 重要
Network
tandoor recipes tandoorのrecipesにおけるHTTP ヘッダのスクリプト構文の不適切な無効化に関する脆弱性 CWE-644
HTTP ヘッダのスクリプト構文の不適切な無効化
CVE-2026-33149 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
2440 4.6 警告
Network
Docmost Docmost Docmostにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33193 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315301 9.8 CRITICAL
Network
archilles newsworld admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and s… CWE-522
 Insufficiently Protected Credentials
CVE-2005-3435 2024-02-9 12:13 2005-11-2 Show GitHub Exploit DB Packet Storm
315302 7.5 HIGH
Network
openssl
canonical
openssl
ubuntu_linux
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certi… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2005-2946 2024-02-9 12:13 2005-09-17 Show GitHub Exploit DB Packet Storm
315303 - armagetronad armagetron_advanced
armagetron
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) clai… CWE-129
 Improper Validation of Array Index
CVE-2005-0369 2024-02-9 12:13 2005-05-2 Show GitHub Exploit DB Packet Storm
315304 9.8 CRITICAL
Network
citrusdb citrusdb CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating t… CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2005-0408 2024-02-9 12:13 2005-02-14 Show GitHub Exploit DB Packet Storm
315305 7.5 HIGH
Network
teekai tracking_online TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 has… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2002-2058 2024-02-9 12:13 2002-12-31 Show GitHub Exploit DB Packet Storm
315306 7.5 HIGH
Network
postgresql postgresql PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2002-1657 2024-02-9 12:06 2002-12-31 Show GitHub Exploit DB Packet Storm
315307 5.5 MEDIUM
Local
busybox
avaya
busybox
message_networking
aura_sip_enablement_services
aura_application_enablement_services
messaging_storage_server
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2006-1058 2024-02-9 12:05 2006-04-4 Show GitHub Exploit DB Packet Storm
315308 6.1 MEDIUM
Network
freescripts visitorbook_le FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site script… CWE-346
 Origin Validation Error
CVE-2003-0981 2024-02-9 11:53 2004-01-5 Show GitHub Exploit DB Packet Storm
315309 7.5 HIGH
Network
6tunnel_project 6tunnel 6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to … CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2001-0830 2024-02-9 11:52 2001-12-6 Show GitHub Exploit DB Packet Storm
315310 - apache
debian
http_server
debian_linux
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct X… CWE-444
HTTP Request Smuggling
CVE-2005-2088 2024-02-9 11:40 2005-07-5 Show GitHub Exploit DB Packet Storm