Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2681 9.1 緊急
Network
BMC Software BMC FootPrints ITSM BMC SoftwareのBMC FootPrints ITSMにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2025-71257 2026-04-24 11:38 2026-03-19 Show GitHub Exploit DB Packet Storm
2682 7.1 重要
Network
BMC Software BMC FootPrints ITSM BMC SoftwareのBMC FootPrints ITSMにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2025-71258 2026-04-24 11:38 2026-03-19 Show GitHub Exploit DB Packet Storm
2683 7.1 重要
Network
BMC Software BMC FootPrints ITSM BMC SoftwareのBMC FootPrints ITSMにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2025-71259 2026-04-24 11:38 2026-03-19 Show GitHub Exploit DB Packet Storm
2684 8.8 重要
Network
BMC Software BMC FootPrints ITSM BMC SoftwareのBMC FootPrints ITSMにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-71260 2026-04-24 11:38 2026-03-19 Show GitHub Exploit DB Packet Storm
2685 6.1 警告
Network
アドビシステムズ Adobe Connect
Adobe Connect Desktop Application
アドビのAdobe Connect等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-21331 2026-04-24 11:38 2026-04-14 Show GitHub Exploit DB Packet Storm
2686 5.4 警告
Network
オラクル PeopleSoft Enterprise HCM Shared Components オラクルのPeoplesoft Enterprise Hcm Shared Componentsにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-22019 2026-04-24 11:38 2026-04-21 Show GitHub Exploit DB Packet Storm
2687 6.1 警告
Adjacent
Schneider Electric PowerChute Serial Shutdown Schneider Electric のPowerChute Serial Shutdownにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-2399 2026-04-24 11:38 2026-04-14 Show GitHub Exploit DB Packet Storm
2688 4.3 警告
Network
Schneider Electric PowerChute Serial Shutdown Schneider Electric のPowerChute Serial ShutdownにおけるCRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2026-2400 2026-04-24 11:38 2026-04-14 Show GitHub Exploit DB Packet Storm
2689 5 警告
Local
Schneider Electric PowerChute Serial Shutdown Schneider Electric のPowerChute Serial Shutdownにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-2401 2026-04-24 11:38 2026-04-14 Show GitHub Exploit DB Packet Storm
2690 5.3 警告
Network
Schneider Electric PowerChute Serial Shutdown Schneider Electric のPowerChute Serial Shutdownにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2026-2402 2026-04-24 11:38 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315091 - maxdev md-pro SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbi… CWE-89
SQL Injection
CVE-2006-1676 2024-02-14 10:17 2006-04-11 Show GitHub Exploit DB Packet Storm
315092 - maxdev md-pro MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php. CWE-200
Information Exposure
CVE-2006-1677 2024-02-14 10:17 2006-04-11 Show GitHub Exploit DB Packet Storm
315093 - squery squery Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in… CWE-94
Code Injection
CVE-2006-1688 2024-02-14 10:17 2006-04-11 Show GitHub Exploit DB Packet Storm
315094 - crafty_syntax_image_gallery crafty_syntax_image_gallery SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary S… NVD-CWE-Other
CVE-2006-1667 2024-02-14 10:17 2006-04-7 Show GitHub Exploit DB Packet Storm
315095 - crafty_syntax_image_gallery crafty_syntax_image_gallery newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a mult… NVD-CWE-Other
CVE-2006-1668 2024-02-14 10:17 2006-04-7 Show GitHub Exploit DB Packet Storm
315096 - 3dsrc monalbum Multiple SQL injection vulnerabilities in MonAlbum 0.8.7 allow remote attackers to execute arbitrary SQL commands via (1) the pc parameter in (a) index.php and (2) pnom, (3) pcourriel, and (4) pcomme… NVD-CWE-Other
CVE-2006-1585 2024-02-14 10:17 2006-04-3 Show GitHub Exploit DB Packet Storm
315097 - trend_micro pc-cillin_2006 Trend Micro PC-cillin Internet Security 2006 14.00.1485 and 14.10.0.1023, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying executable programs s… NVD-CWE-Other
CVE-2006-1379 2024-02-14 10:17 2006-03-24 Show GitHub Exploit DB Packet Storm
315098 - trendmicro interscan_messaging_security_suite ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local us… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-1380 2024-02-14 10:17 2006-03-24 Show GitHub Exploit DB Packet Storm
315099 - trend_micro officescan Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe. NVD-CWE-Other
CVE-2006-1381 2024-02-14 10:17 2006-03-24 Show GitHub Exploit DB Packet Storm
315100 - glftpd glftpd Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address. NVD-CWE-Other
CVE-2006-1253 2024-02-14 10:17 2006-03-19 Show GitHub Exploit DB Packet Storm