Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2691 4.3 警告
Network
dnnsoftware dotnetnuke dnnsoftwareのdotnetnukeにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-40305 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2692 6.5 警告
Network
dnnsoftware dotnetnuke dnnsoftwareのdotnetnukeにおける不十分なランダム値の使用に関する脆弱性 CWE-330
不十分なランダム値の使用
CVE-2026-40306 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2693 8 重要
Network
dnnsoftware dotnetnuke dnnsoftwareのdotnetnukeにおける代替 XSS 構文の不適切な無効化に関する脆弱性 CWE-87
代替 XSS 構文の不適切な無効化
CVE-2026-40321 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2694 5.3 警告
Network
The FastAPI Expert python-multipart The FastAPI Expertのpython-multipartにおける複数の脆弱性 CWE-400
CWE-834
CVE-2026-40347 2026-04-27 10:48 2026-04-18 Show GitHub Exploit DB Packet Storm
2695 5.4 警告
Network
wger wger wger Projectのwgerにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40353 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2696 7.6 重要
Network
wger wger wger Projectのwgerにおける複数の脆弱性 CWE-284
CWE-862
CVE-2026-40474 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2697 9 緊急
Network
Thymeleaf Thymeleaf Thymeleafにおける複数の脆弱性 CWE-1336
CWE-917
CVE-2026-40477 2026-04-27 10:48 2026-04-17 Show GitHub Exploit DB Packet Storm
2698 9 緊急
Network
Thymeleaf Thymeleaf Thymeleafにおける複数の脆弱性 CWE-1336
CWE-917
CVE-2026-40478 2026-04-27 10:47 2026-04-17 Show GitHub Exploit DB Packet Storm
2699 7.1 重要
Local
Craig J. Bass (craigjbass) ClearanceKit Craig J. Bass (craigjbass)のClearanceKitにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-40599 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2700 4.4 警告
Local
Craig J. Bass (craigjbass) ClearanceKit Craig J. Bass (craigjbass)のClearanceKitにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-40604 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
316271 - guillaumegardey biborb Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the… CWE-22
Path Traversal
CVE-2005-0253 2024-02-3 01:50 2005-05-2 Show GitHub Exploit DB Packet Storm
316272 - guillaumegardey biborb BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2005-0254 2024-02-3 01:44 2005-05-2 Show GitHub Exploit DB Packet Storm
316273 - guillaumegardey biborb Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter. CWE-79
Cross-site Scripting
CVE-2005-0251 2024-02-3 01:42 2005-05-2 Show GitHub Exploit DB Packet Storm
316274 7.0 HIGH
Local
linux
opensuse
suse
debian
linux_kernel
opensuse
linux_enterprise_server
linux_enterprise_desktop
linux_enterprise_high_availability_extension
debian_linux
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2010-1437 2024-02-3 01:38 2010-05-8 Show GitHub Exploit DB Packet Storm
316275 - postgresql
trustix
mandrakesoft
redhat
postgresql
secure_linux
mandrake_linux_corporate_server
enterprise_linux_desktop
enterprise_linux
mandrake_linux
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files. NVD-CWE-Other
CVE-2004-0977 2024-02-3 01:33 2005-02-9 Show GitHub Exploit DB Packet Storm
316276 9.8 CRITICAL
Network
mit
openpkg
debian
kerberos_5
openpkg
debian_linux
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code. CWE-415
 Double Free
CVE-2004-0772 2024-02-3 00:27 2004-10-20 Show GitHub Exploit DB Packet Storm
316277 - mit
debian
redhat
kerberos_5
debian_linux
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow… CWE-415
 Double Free
CVE-2004-0642 2024-02-3 00:27 2004-09-28 Show GitHub Exploit DB Packet Storm
316278 9.8 CRITICAL
Network
mit
apple
debian
kerberos_5
mac_os_x_server
mac_os_x
debian_linux
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions. CWE-415
 Double Free
CVE-2005-1689 2024-02-3 00:24 2005-07-18 Show GitHub Exploit DB Packet Storm
316279 7.8 HIGH
Local
microsoft outlook
internet_explorer
windows_xp
windows_server_2003
windows_98
windows_me
windows_98se
windows_nt
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image. CWE-415
 Double Free
CVE-2003-1048 2024-02-3 00:23 2004-07-27 Show GitHub Exploit DB Packet Storm
316280 9.8 CRITICAL
Network
openssl openssl Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 … CWE-415
 Double Free
CVE-2003-0545 2024-02-3 00:23 2003-11-17 Show GitHub Exploit DB Packet Storm