Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2961 6.1 警告
Network
WSO2 WSO2 Identity Server WSO2のWSO2 Identity Serverにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-10503 2026-05-7 12:07 2026-04-29 Show GitHub Exploit DB Packet Storm
2962 5.3 警告
Network
MCPHub MCPHub MCPHubにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-13822 2026-05-7 12:07 2026-04-14 Show GitHub Exploit DB Packet Storm
2963 5.3 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2025-14688 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
2964 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-36122 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
2965 5.3 警告
Network
HCL Technologies Limited HCL AION HCL Technologies LimitedのHCL AIONにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52641 2026-05-7 12:07 2026-04-15 Show GitHub Exploit DB Packet Storm
2966 6.4 警告
Local
レッドハット Ansible Automation Platform レッドハットのAnsible Automation Platformにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57847 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
2967 6.7 警告
Local
レッドハット Red Hat Advanced Cluster Management for Kubernetes レッドハットのRed Hat Advanced Cluster Management for Kubernetesにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57851 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
2968 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2026-1577 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
2969 5.5 警告
Local
サムスン android サムスンのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21023 2026-05-7 12:06 2026-04-29 Show GitHub Exploit DB Packet Storm
2970 4.8 警告
Network
VMware Spring Security VMwareのSpring SecurityにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-22751 2026-05-7 12:06 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346711 - francisco_burzi
oscommerce
paul_laudanski
trustix
php-nuke
osc2nuke
betanc_php-nuke
secure_linux
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERV… NVD-CWE-Other
CVE-2004-2044 2017-07-11 10:31 2004-06-1 Show GitHub Exploit DB Packet Storm
346712 - conceptronic cadslr1_adsl_router The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long usern… NVD-CWE-Other
CVE-2004-2045 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346713 - apc powerchute Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors. NVD-CWE-Other
CVE-2004-2046 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346714 - easyweb easyweb_filemanager Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter. NVD-CWE-Other
CVE-2004-2047 2017-07-11 10:31 2004-07-23 Show GitHub Exploit DB Packet Storm
346715 - esesix thintune_extreme
thintune_l
thintune_m
thintune_mobile
thintune_s
thintune_xm
thintune_xs
radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain acce… NVD-CWE-Other
CVE-2004-2048 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346716 - esesix thintune_extreme
thintune_l
thintune_m
thintune_mobile
thintune_s
thintune_xm
thintune_xs
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain acc… NVD-CWE-Other
CVE-2004-2049 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346717 - esesix thintune_extreme
thintune_l
thintune_m
thintune_mobile
thintune_s
thintune_xm
thintune_xs
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshe… NVD-CWE-Other
CVE-2004-2050 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346718 - esesix thintune_extreme
thintune_l
thintune_m
thintune_mobile
thintune_s
thintune_xm
thintune_xs
The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL. NVD-CWE-Other
CVE-2004-2051 2017-07-11 10:31 2004-07-24 Show GitHub Exploit DB Packet Storm
346719 - easyins easyins PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter. NVD-CWE-Other
CVE-2004-2053 2017-07-11 10:31 2004-07-24 Show GitHub Exploit DB Packet Storm
346720 - phpbb_group phpbb CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to … NVD-CWE-Other
CVE-2004-2054 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm