Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
341 9.1 緊急
Network
EspoCRM EspoCRM EspoCRMにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-33656 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
342 7.2 重要
Network
EspoCRM EspoCRM EspoCRMにおける相対パストラバーサルの脆弱性 New CWE-23
相対的パストラバーサル
CVE-2026-33733 2026-04-30 12:30 2026-04-22 Show GitHub Exploit DB Packet Storm
343 7.5 重要
Network
FirebirdSQL Firebird FirebirdSQLのFirebirdにおける不正な構文構造の不適切な処理に関する脆弱性 New CWE-228
不正な構文構造の不適切な処理
CVE-2026-34232 2026-04-30 12:30 2026-04-17 Show GitHub Exploit DB Packet Storm
344 5.3 警告
Network
オラクル Oracle GoldenGate オラクルのOracle GoldenGateにおける情報漏えいに関する脆弱性 New CWE-200
情報漏えい
CVE-2026-34273 2026-04-30 12:30 2026-04-21 Show GitHub Exploit DB Packet Storm
345 8.1 重要
Network
getkirby kirby getkirbyのkirbyにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 New CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-34587 2026-04-30 12:30 2026-04-24 Show GitHub Exploit DB Packet Storm
346 9 緊急
Network
Ci4-cms-erp Ci4MS Ci4-cms-erpのCi4MSにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-34989 2026-04-30 12:30 2026-04-6 Show GitHub Exploit DB Packet Storm
347 7.5 重要
Network
Linux Foundation Antrea Linux FoundationのAntreaにおける重要なデータの暗号化の欠如に関する脆弱性 New CWE-311
重要なデータの暗号化の欠如
CVE-2026-34992 2026-04-30 12:29 2026-04-6 Show GitHub Exploit DB Packet Storm
348 7.5 重要
Network
FirebirdSQL Firebird FirebirdSQLのFirebirdにおけるゼロ除算に関する脆弱性 New CWE-369
ゼロ除算
CVE-2026-35215 2026-04-30 12:29 2026-04-17 Show GitHub Exploit DB Packet Storm
349 8 重要
Adjacent
フィリップス Hue Bridge V2 ファームウェア フィリップスのHue Bridge V2 ファームウェアにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-3555 2026-04-30 12:29 2026-03-16 Show GitHub Exploit DB Packet Storm
350 8.8 重要
Adjacent
フィリップス Hue Bridge V2 ファームウェア フィリップスのHue Bridge V2 ファームウェアにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-3556 2026-04-30 12:29 2026-03-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313481 - dotnetindex active_news_manager SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. NVD-CWE-Other
CVE-2005-1780 2024-02-14 10:17 2005-05-31 Show GitHub Exploit DB Packet Storm
313482 - zongg zongg SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NVD-CWE-Other
CVE-2005-1785 2024-02-14 10:17 2005-05-31 Show GitHub Exploit DB Packet Storm
313483 - online_solutions_for_educators online_solutions_for_educators SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password. NVD-CWE-Other
CVE-2005-1805 2024-02-14 10:17 2005-05-28 Show GitHub Exploit DB Packet Storm
313484 - distinct_web_creations newsletterez SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. NVD-CWE-Other
CVE-2005-1750 2024-02-14 10:17 2005-05-25 Show GitHub Exploit DB Packet Storm
313485 - funkyasp funkyasp_ad_system SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter. NVD-CWE-Other
CVE-2005-1786 2024-02-14 10:17 2005-05-25 Show GitHub Exploit DB Packet Storm
313486 - xine gxine Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format st… NVD-CWE-Other
CVE-2005-1692 2024-02-14 10:17 2005-05-24 Show GitHub Exploit DB Packet Storm
313487 - web-app.org webapp apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. CWE-20
 Improper Input Validation 
CVE-2005-1628 2024-02-14 10:17 2005-05-17 Show GitHub Exploit DB Packet Storm
313488 - atinegar sigma_isp_manager SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields. NVD-CWE-Other
CVE-2005-1639 2024-02-14 10:17 2005-05-17 Show GitHub Exploit DB Packet Storm
313489 - fusion sbx index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code… NVD-CWE-Other
CVE-2005-1596 2024-02-14 10:17 2005-05-16 Show GitHub Exploit DB Packet Storm
313490 - darrel_oneil asp_virtual_news_manager SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter. NVD-CWE-Other
CVE-2005-1573 2024-02-14 10:17 2005-05-11 Show GitHub Exploit DB Packet Storm