Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2441 9.8 緊急
Network
マイクロソフト Microsoft Entra ID Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-33843 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
2442 4.3 警告
Network
Joomla! Joomla! Joomla!におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-35220 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2443 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-35221 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2444 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-35222 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2445 8.8 重要
Network
FreeRDP FreeRDP FreeRDPにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40033 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2446 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40383 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2447 7.2 重要
Network
IBM Engineering Lifecycle Management IBMのEngineering Lifecycle Managementにおける危険なメソッドや機能の公開に関する脆弱性 CWE-749
危険なメソッドや機能の公開
CVE-2026-4051 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
2448 6.5 警告
Network
struktur AG libheif struktur AGのlibheifにおける複数の脆弱性 CWE-125
CWE-476
CVE-2026-41069 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
2449 8.1 重要
Network
struktur AG libheif struktur AGのlibheifにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-41071 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
2450 9.3 緊急
Network
マイクロソフト Microsoft 365 Copilot Microsoft Copilot Tampering Vulnerability CWE-77
コマンドインジェクション
CVE-2026-41090 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345171 - bardon_data_systems winu WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration. NVD-CWE-Other
CVE-2000-0988 2017-12-19 11:29 2000-12-19 Show GitHub Exploit DB Packet Storm
345172 - redhat
trustix
linux
secure_linux
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse … NVD-CWE-Other
CVE-2000-1009 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345173 - open_source_development_network slashcode The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary comman… NVD-CWE-Other
CVE-2000-1015 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345174 - alt-n mdaemon Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. NVD-CWE-Other
CVE-2000-1020 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345175 - alt-n mdaemon Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. NVD-CWE-Other
CVE-2000-1021 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345176 - alabanza control_panel The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program. NVD-CWE-Other
CVE-2000-1023 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345177 - unify ewave_servletexec eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExe… NVD-CWE-Other
CVE-2000-1025 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345178 - cat_soft serv-u Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users. NVD-CWE-Other
CVE-2000-1033 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345179 - qbik wingate Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses … NVD-CWE-Other
CVE-2000-1048 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm
345180 - macromedia jrun Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JS… NVD-CWE-Other
CVE-2000-1053 2017-12-19 11:29 2000-12-11 Show GitHub Exploit DB Packet Storm