Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2441 6.5 警告
Network
Elasticsearch B.V. Kibana Elasticsearch B.V.のKibanaにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-33461 2026-04-24 11:30 2026-04-8 Show GitHub Exploit DB Packet Storm
2442 4.8 警告
Network
cryptomator cryptomator cryptomatorにおける複数の脆弱性 CWE-305
CWE-319
CVE-2026-33472 2026-04-24 11:30 2026-04-16 Show GitHub Exploit DB Packet Storm
2443 5.5 警告
Network
Pinchtab PinchTab PinchtabのPinchTabにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-33619 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
2444 6.5 警告
Network
Pinchtab PinchTab PinchtabのPinchTabにおける複数の脆弱性 CWE-290
CWE-770
CVE-2026-33621 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
2445 7.5 重要
Network
InternLM LMDeploy InternLMのLMDeployにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-33626 2026-04-24 11:30 2026-04-20 Show GitHub Exploit DB Packet Storm
2446 6.1 警告
Network
Project Jupyter JupyterHub Project JupyterのJupyterHubにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-33709 2026-04-24 11:30 2026-04-3 Show GitHub Exploit DB Packet Storm
2447 7.2 重要
Network
Chamilo Association Chamilo LMS Chamilo AssociationのChamilo LMSにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-33714 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
2448 7.2 重要
Network
Chamilo Association Chamilo LMS Chamilo AssociationのChamilo LMSにおける複数の脆弱性 CWE-306
CWE-918
CVE-2026-33715 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
2449 9.1 緊急
Network
Open JS Foundation fastify/middie Open JS Foundationの@fastify/middieにおける解釈の競合に関する脆弱性 CWE-436
解釈の競合
CVE-2026-33804 2026-04-24 11:30 2026-04-16 Show GitHub Exploit DB Packet Storm
2450 4.3 警告
Network
LangGenius, Inc. Dify LangGenius, Inc.のDifyにおける複数の脆弱性 CWE-284
CWE-863
CVE-2026-34082 2026-04-24 11:30 2026-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314791 - ibm aix AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods. CWE-203
 Information Exposure Through Discrepancy
CVE-2004-0243 2024-02-14 23:30 2004-11-23 Show GitHub Exploit DB Packet Storm
314792 5.5 MEDIUM
Local
- - Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932 - CVE-2024-0584 2024-02-14 15:15 2024-01-16 Show GitHub Exploit DB Packet Storm
314793 7.8 HIGH
Local
- - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. - CVE-2023-42915 2024-02-14 12:15 2024-01-23 Show GitHub Exploit DB Packet Storm
314794 - jvehicles com_jvehicles SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlist… CWE-89
SQL Injection
CVE-2010-1873 2024-02-14 10:17 2010-05-12 Show GitHub Exploit DB Packet Storm
314795 - vmware player
ace
workstation
server
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 bef… CWE-134
Use of Externally-Controlled Format String
CVE-2009-4811 2024-02-14 10:17 2010-04-28 Show GitHub Exploit DB Packet Storm
314796 - hp operations_manager Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argu… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-1033 2024-02-14 10:17 2010-04-21 Show GitHub Exploit DB Packet Storm
314797 - tukeva password_reminder TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. CWE-255
Credentials Management
CVE-2009-4781 2024-02-14 10:17 2010-04-21 Show GitHub Exploit DB Packet Storm
314798 - microsoft windows_xp
windows_vista
The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption… CWE-399
 Resource Management Errors
CVE-2010-1098 2024-02-14 10:17 2010-03-25 Show GitHub Exploit DB Packet Storm
314799 - kiss-software com_ksadvertiser SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid para… CWE-89
SQL Injection
CVE-2010-0946 2024-02-14 10:17 2010-03-9 Show GitHub Exploit DB Packet Storm
314800 - visualizationlibrary visualization_library Multiple unspecified vulnerabilities in Visualization Library before 2009.08.812 have unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2010-0937 2024-02-14 10:17 2010-03-9 Show GitHub Exploit DB Packet Storm