Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2701 4.8 警告
Network
mitmproxy mitmproxy mitmproxyにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-40606 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2702 7.5 重要
Network
coturn project coturn coturn projectのcoturnにおける不正な型変換に関する脆弱性 CWE-704
不正な型変換またはキャスト
CVE-2026-40613 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2703 8.8 重要
Network
goshs goshs goshsにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40876 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2704 7.5 重要
Network
- NestJSにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-40879 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2705 7.6 重要
Network
openremote openremote openremoteにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-40882 2026-04-27 10:47 2026-04-22 Show GitHub Exploit DB Packet Storm
2706 8.3 重要
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40925 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2707 8.3 重要
Network
RustFS RustFS RustFSにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40937 2026-04-27 10:47 2026-04-22 Show GitHub Exploit DB Packet Storm
2708 7.1 重要
Network
WWBN AVideo WWBNのAVideoにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-41057 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2709 8.1 重要
Network
WWBN AVideo WWBNのAVideoにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41058 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2710 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41060 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
316341 - deluxebb deluxebb DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupl… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2006-4558 2024-01-27 04:02 2006-09-6 Show GitHub Exploit DB Packet Storm
316342 - duware_dubanner_project duware_dubanner add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be b… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2006-2428 2024-01-27 04:01 2006-05-17 Show GitHub Exploit DB Packet Storm
316343 - rockliffe mailsite_express Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the ca… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2005-3288 2024-01-27 04:01 2005-10-23 Show GitHub Exploit DB Packet Storm
316344 - linux
canonical
debian
mandriva
linux_kernel
ubuntu_linux
debian_linux
linux
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from … CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2005-3181 2024-01-27 03:56 2005-10-12 Show GitHub Exploit DB Packet Storm
316345 - linux linux_kernel The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activ… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2004-0427 2024-01-27 03:56 2004-07-7 Show GitHub Exploit DB Packet Storm
316346 - openbsd openbsd Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP P… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2004-0222 2024-01-27 03:55 2004-05-4 Show GitHub Exploit DB Packet Storm
316347 - freebsd freebsd Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count fo… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2002-0574 2024-01-27 03:55 2002-07-3 Show GitHub Exploit DB Packet Storm
316348 - proftpd
mandrakesoft
debian
conectiva
proftpd
mandrake_linux
debian_linux
linux
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2001-0136 2024-01-27 03:53 2001-03-12 Show GitHub Exploit DB Packet Storm
316349 5.8 MEDIUM
Network
chillcreations com_ccnewsletter Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in … CWE-22
Path Traversal
CVE-2010-0467 2024-01-27 02:44 2010-02-3 Show GitHub Exploit DB Packet Storm
316350 9.8 CRITICAL
Network
debian
canonical
lintian
debian_linux
ubuntu_linux
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive i… CWE-22
Path Traversal
CVE-2009-4013 2024-01-27 02:44 2010-02-3 Show GitHub Exploit DB Packet Storm