Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2641 5.9 警告
Network
PowerDNS PowerDNS Recursor PowerDNSのPowerDNS Recursorにおける完全性チェックの欠如に関する脆弱性 CWE-353
完全性チェックの欠如
CVE-2026-33261 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2642 5.9 警告
Network
PowerDNS PowerDNS Recursor PowerDNSのPowerDNS RecursorにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-33262 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2643 8.7 重要
Local
Linaro OP-TEE Trusted OS LinaroのOP-TEE Trusted OSにおける複数の脆弱性 CWE-125
CWE-787
CVE-2026-33317 2026-04-30 12:30 2026-04-24 Show GitHub Exploit DB Packet Storm
2644 8.8 重要
Network
Actual Budget Actual Actual BudgetのActualにおける複数の脆弱性 CWE-284
CWE-862
CVE-2026-33318 2026-04-30 12:30 2026-04-24 Show GitHub Exploit DB Packet Storm
2645 7.5 重要
Network
FirebirdSQL Firebird FirebirdSQLのFirebirdにおける複数の脆弱性 CWE-120
CWE-502
CVE-2026-33337 2026-04-30 12:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2646 4.9 警告
Network
PowerDNS PowerDNS Recursor PowerDNSのPowerDNS RecursorにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-33600 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2647 4.9 警告
Network
PowerDNS PowerDNS Recursor PowerDNSのPowerDNS RecursorにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-33601 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2648 9.1 緊急
Network
EspoCRM EspoCRM EspoCRMにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-33656 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2649 7.2 重要
Network
EspoCRM EspoCRM EspoCRMにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-33733 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
2650 7.5 重要
Network
FirebirdSQL Firebird FirebirdSQLのFirebirdにおける不正な構文構造の不適切な処理に関する脆弱性 CWE-228
不正な構文構造の不適切な処理
CVE-2026-34232 2026-04-30 12:30 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317281 - cutephp cutenews Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a temp… CWE-94
Code Injection
CVE-2005-1876 2024-02-14 01:19 2005-06-9 Show GitHub Exploit DB Packet Storm
317282 - flatnuke flatnuke Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be… CWE-94
Code Injection
CVE-2005-1894 2024-02-14 01:19 2005-06-9 Show GitHub Exploit DB Packet Storm
317283 7.5 HIGH
Network
symfony twig The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication inform… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2001-1537 2024-02-14 01:19 2001-12-31 Show GitHub Exploit DB Packet Storm
317284 7.5 HIGH
Network
dlink dsl-504t_firmware D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2005-1828 2024-02-14 01:17 2005-05-26 Show GitHub Exploit DB Packet Storm
317285 7.5 HIGH
Network
broadcom bluecoat_security_gateway The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which all… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2004-2397 2024-02-14 01:17 2004-12-31 Show GitHub Exploit DB Packet Storm
317286 - myupb ultimate_php_board Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is execute… CWE-94
Code Injection
CVE-2003-0395 2024-02-14 01:14 2003-07-2 Show GitHub Exploit DB Packet Storm
317287 5.5 MEDIUM
Local
capturix scanshare Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2005-2209 2024-02-14 01:09 2005-07-11 Show GitHub Exploit DB Packet Storm
317288 - - - Rejected reason: **REJECT** Not a valid vulnerability. - CVE-2024-0707 2024-02-13 23:15 2024-02-13 Show GitHub Exploit DB Packet Storm
317289 - - - Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead. - CVE-2024-1420 2024-02-13 00:15 2024-02-13 Show GitHub Exploit DB Packet Storm
317290 7.5 HIGH
Network
phprank phprank phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2002-1800 2024-02-10 12:06 2002-12-31 Show GitHub Exploit DB Packet Storm