Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2561 8 重要
Network
マイクロソフト Microsoft Power Apps Microsoft Power Apps のリモートでコードが実行される脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2026-32172 2026-05-1 10:48 2026-04-23 Show GitHub Exploit DB Packet Storm
2562 7.1 重要
Local
マイクロソフト Microsoft Office
Microsoft Excel
Office Long Term Servicing Channel (LTSC)
Microsoft 365 Apps
Microsoft Office Online Server
Microsoft Excel の情報漏えいの脆弱性 CWE-125
境界外読み取り
CVE-2026-32188 2026-05-1 10:48 2026-04-14 Show GitHub Exploit DB Packet Storm
2563 7.8 重要
Local
マイクロソフト Microsoft Office
Microsoft Excel
Office Long Term Servicing Channel (LTSC)
Microsoft 365 Apps
Microsoft Office Online Server
Microsoft Excel のリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32189 2026-05-1 10:48 2026-04-14 Show GitHub Exploit DB Packet Storm
2564 8.4 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Office Long Term Servicing Channel (LTSC)
Microsoft Office のリモート コードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32190 2026-05-1 10:48 2026-04-14 Show GitHub Exploit DB Packet Storm
2565 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Office Long Term Servicing Channel (LTSC)
Microsoft Word のリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33095 2026-05-1 10:48 2026-04-14 Show GitHub Exploit DB Packet Storm
2566 9.3 緊急
Network
マイクロソフト Microsoft 365 Copilot Microsoft 365 Copilot の特権昇格の脆弱性 CWE-601
オープンリダイレクト
CVE-2026-33102 2026-05-1 10:48 2026-04-23 Show GitHub Exploit DB Packet Storm
2567 8.4 重要
Local
マイクロソフト Microsoft 365 Apps
Office Long Term Servicing Channel (LTSC)
Microsoft Word のリモートでコードが実行される脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-33114 2026-05-1 10:48 2026-04-14 Show GitHub Exploit DB Packet Storm
2568 8.4 重要
Local
マイクロソフト Microsoft 365 Apps
Office Long Term Servicing Channel (LTSC)
Microsoft Word のリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33115 2026-05-1 10:47 2026-04-14 Show GitHub Exploit DB Packet Storm
2569 7.8 重要
Local
ggml.ai llama.cpp ggml.aiのllama.cppにおける複数の脆弱性 CWE-122
CWE-190
CVE-2026-33298 2026-05-1 10:47 2026-03-24 Show GitHub Exploit DB Packet Storm
2570 6.1 警告
Local
マイクロソフト Microsoft 365 Apps
Office Long Term Servicing Channel (LTSC)
Microsoft Word の情報漏えいの脆弱性 CWE-125
境界外読み取り
CVE-2026-33822 2026-05-1 10:47 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317611 8.8 HIGH
Network
openbb openbb Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0… CWE-352
 Origin Validation Error
CVE-2004-1967 2024-02-9 05:46 2004-04-25 Show GitHub Exploit DB Packet Storm
317612 7.8 HIGH
Local
lynx_project lynx Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL tha… CWE-346
 Origin Validation Error
CVE-1999-1549 2024-02-9 05:46 1999-11-16 Show GitHub Exploit DB Packet Storm
317613 7.5 HIGH
Network
cisco ip_phone_7940_firmware
ip_phone_7960_firmware
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages suc… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2005-2181 2024-02-9 05:45 2005-07-11 Show GitHub Exploit DB Packet Storm
317614 7.5 HIGH
Network
grandstream bt-100_firmware Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spo… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2005-2182 2024-02-9 05:45 2005-07-11 Show GitHub Exploit DB Packet Storm
317615 9.8 CRITICAL
Network
sgi irix The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a pass… CWE-346
 Origin Validation Error
CVE-2003-0174 2024-02-9 05:45 2003-05-12 Show GitHub Exploit DB Packet Storm
317616 6.5 MEDIUM
Network
ubbcentral ubb.threads Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow … CWE-352
 Origin Validation Error
CVE-2005-2059 2024-02-9 05:44 2005-06-29 Show GitHub Exploit DB Packet Storm
317617 4.3 MEDIUM
Network
invisioncommunity gallery Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) del… CWE-352
 Origin Validation Error
CVE-2005-1947 2024-02-9 05:44 2005-06-9 Show GitHub Exploit DB Packet Storm
317618 9.8 CRITICAL
Network
bea weblogic_server BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without ha… CWE-459
 Incomplete Cleanup
CVE-2005-1744 2024-02-9 05:35 2005-05-24 Show GitHub Exploit DB Packet Storm
317619 7.5 HIGH
Network
accessdata secureclean SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be … CWE-459
 Incomplete Cleanup
CVE-2002-2070 2024-02-9 05:35 2002-12-31 Show GitHub Exploit DB Packet Storm
317620 7.5 HIGH
Network
microsoft windows_nt Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing … CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-1999-1127 2024-02-9 05:35 1999-12-31 Show GitHub Exploit DB Packet Storm