Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2521 9 緊急
Network
Jenkins プロジェクト GitHub JenkinsのGitHubにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42523 2026-05-7 10:51 2026-04-29 Show GitHub Exploit DB Packet Storm
2522 8 重要
Network
Jenkins プロジェクト HTML Publisher Plugin JenkinsのHTML Publisher Pluginにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42524 2026-05-7 10:51 2026-04-29 Show GitHub Exploit DB Packet Storm
2523 4.3 警告
Network
Jenkins プロジェクト Azure AD JenkinsのAzure ADにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-42525 2026-05-7 10:51 2026-04-29 Show GitHub Exploit DB Packet Storm
2524 8.8 重要
Adjacent
TP-LINK Technologies TL-WR841N ファームウェア TP-LINK TechnologiesのTL-WR841N ファームウェアにおけるデフォルトの暗号鍵の使用に関する脆弱性 CWE-1394
デフォルトの暗号鍵の使用
CVE-2026-5039 2026-05-7 10:51 2026-04-23 Show GitHub Exploit DB Packet Storm
2525 7.3 重要
Network
GNU Project GNU C Library GNU ProjectのGNU C Libraryにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-5435 2026-05-7 10:51 2026-04-28 Show GitHub Exploit DB Packet Storm
2526 7.5 重要
Network
Progress Software Corporation Telerik UI for ASP.NET AJAX Progress Software CorporationのTelerik UI for ASP.NET AJAXにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-6022 2026-05-7 10:51 2026-04-22 Show GitHub Exploit DB Packet Storm
2527 9.8 緊急
Network
Progress Software Corporation Telerik UI for ASP.NET AJAX Progress Software CorporationのTelerik UI for ASP.NET AJAXにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-6023 2026-05-7 10:51 2026-04-22 Show GitHub Exploit DB Packet Storm
2528 2.7
Network
Tanium Tanium Server TaniumのTanium Serverにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-6408 2026-05-7 10:51 2026-04-22 Show GitHub Exploit DB Packet Storm
2529 5.5 警告
Local
Wireshark Wireshark WiresharkにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-6525 2026-05-7 10:51 2026-05-2 Show GitHub Exploit DB Packet Storm
2530 7.5 重要
Network
TYPO3 Association TYPO3 TYPO3 AssociationのTYPO3における重要な情報の平文保存に関する脆弱性 CWE-312
重要な情報の平文保存
CVE-2026-6553 2026-05-7 10:51 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317641 9.8 CRITICAL
Network
openbsd openssh Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is usin… CWE-190
 Integer Overflow or Wraparound
CVE-2002-0639 2024-02-9 03:37 2002-07-3 Show GitHub Exploit DB Packet Storm
317642 7.8 HIGH
Local
linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which cau… CWE-190
 Integer Overflow or Wraparound
CVE-2004-2013 2024-02-9 02:59 2004-12-31 Show GitHub Exploit DB Packet Storm
317643 9.8 CRITICAL
Network
wuftpd
redhat
apple
sun
freebsd
netbsd
openbsd
wu-ftpd
wu_ftpd
mac_os_x_server
mac_os_x
solaris
freebsd
netbsd
openbsd
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via command… CWE-193
 Off-by-one Error
CVE-2003-0466 2024-02-9 00:50 2003-08-27 Show GitHub Exploit DB Packet Storm
317644 5.5 MEDIUM
Local
mandrakesoft mandrake_linux The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files. CWE-276
Incorrect Default Permissions 
CVE-2002-1713 2024-02-9 00:50 2002-12-31 Show GitHub Exploit DB Packet Storm
317645 7.8 HIGH
Local
microsoft windows_media_player Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privile… CWE-276
Incorrect Default Permissions 
CVE-2002-1844 2024-02-9 00:50 2002-12-31 Show GitHub Exploit DB Packet Storm
317646 9.8 CRITICAL
Network
suse suse_linux The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. CWE-276
Incorrect Default Permissions 
CVE-1999-0426 2024-02-9 00:50 1999-03-1 Show GitHub Exploit DB Packet Storm
317647 7.8 HIGH
Local
isc bind dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which al… CWE-276
Incorrect Default Permissions 
CVE-2001-0497 2024-02-9 00:49 2001-07-21 Show GitHub Exploit DB Packet Storm
317648 7.5 HIGH
Network
aol aim The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer under… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2005-1891 2024-02-9 00:44 2005-06-9 Show GitHub Exploit DB Packet Storm
317649 9.8 CRITICAL
Network
barton ngircd Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2005-0199 2024-02-9 00:43 2005-05-2 Show GitHub Exploit DB Packet Storm
317650 7.5 HIGH
Network
samba
canonical
ppp
ubuntu_linux
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an inco… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2004-1002 2024-02-9 00:43 2005-03-1 Show GitHub Exploit DB Packet Storm