Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3251 7.1 重要
Local
デル Dell/Alienware Purchased Apps デルのDell/Alienware Purchased Appsにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-27105 2026-05-7 10:53 2026-04-29 Show GitHub Exploit DB Packet Storm
3252 7.8 重要
Local
entechtaiwan TViPort entechtaiwanのTViPortにおける複数の脆弱性 CWE-20
CWE-269
CVE-2026-30769 2026-05-7 10:53 2026-04-29 Show GitHub Exploit DB Packet Storm
3253 5.9 警告
Network
Elasticsearch B.V. Elastic Package Registry Elasticsearch B.V.のElastic Package Registryにおけるデジタル署名の検証に関する脆弱性 CWE-347
デジタル署名の不適切な検証
CVE-2026-33467 2026-05-7 10:53 2026-04-28 Show GitHub Exploit DB Packet Storm
3254 4.4 警告
Local
Mercurycom MIPC252W Firmware MercurycomのMIPC252W Firmwareにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-35901 2026-05-7 10:53 2026-04-27 Show GitHub Exploit DB Packet Storm
3255 6.2 警告
Local
Mercurycom MIPC252W Firmware MercurycomのMIPC252W Firmwareにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2026-35902 2026-05-7 10:53 2026-04-27 Show GitHub Exploit DB Packet Storm
3256 9.8 緊急
Network
Mercurycom MIPC252W Firmware MercurycomのMIPC252W Firmwareにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-35903 2026-05-7 10:53 2026-04-27 Show GitHub Exploit DB Packet Storm
3257 4.8 警告
Network
Apache Software Foundation Apache Storm Prometheus Reporter Apache Software FoundationのApache Storm Prometheus Reporterにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40557 2026-05-7 10:53 2026-04-27 Show GitHub Exploit DB Packet Storm
3258 8.8 重要
Network
minerva minerva Agilonhealth (MphRx)のMinervaにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-5779 2026-05-7 10:53 2026-04-28 Show GitHub Exploit DB Packet Storm
3259 8.1 重要
Network
minerva minerva Agilonhealth (MphRx)のMinervaにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-5780 2026-05-7 10:52 2026-04-28 Show GitHub Exploit DB Packet Storm
3260 8.8 重要
Network
Frappe ERPNext FrappeのERPNextにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2023-54345 2026-05-7 10:52 2026-05-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346991 - jaws jaws Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged sess… NVD-CWE-Other
CVE-2004-2443 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346992 - jaws jaws Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter. NVD-CWE-Other
CVE-2004-2444 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346993 - jaws jaws Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter. NVD-CWE-Other
CVE-2004-2445 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346994 - 1st_class_internet_solutions 1st_class_mail_server Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors. NVD-CWE-Other
CVE-2004-2446 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346995 - 1st_class_internet_solutions 1st_class_mail_server Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index scr… NVD-CWE-Other
CVE-2004-2447 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346996 - cassiopeia
itransact
s-mart_shopping_cart
redicart
S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the databa… NVD-CWE-Other
CVE-2004-2448 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346997 - gamespy roger_wilco_dedicated_server
roger_wilco_graphical_server
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram. NVD-CWE-Other
CVE-2004-2449 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346998 - gamespy roger_wilco
roger_wilco_dedicated_server
roger_wilco_graphical_server
roger_wilco_mark
The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers… NVD-CWE-Other
CVE-2004-2450 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
346999 - - - Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. NVD-CWE-Other
CVE-2004-2451 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
347000 - - - Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag… NVD-CWE-Other
CVE-2004-2452 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm