Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3631 9.9 緊急
Network
Frappe ERPNext FrappeのERPNextにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-44442 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
3632 6.5 警告
Network
Frappe ERPNext FrappeのERPNextにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-44445 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3633 7.5 重要
Network
Frappe ERPNext FrappeのERPNextにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-44446 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3634 7.5 重要
Network
Frappe ERPNext FrappeのERPNextにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-44447 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3635 5.4 警告
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける解釈の競合に関する脆弱性 CWE-436
解釈の競合
CVE-2026-44576 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3636 8.6 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-44578 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3637 7.5 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-44579 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3638 6.1 警告
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44580 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3639 4.7 警告
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44581 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
3640 3.7
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける弱いハッシュの使用に関する脆弱性 CWE-328
脆弱なハッシュの使用
CVE-2026-44582 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345921 - gnu gdb gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb. NVD-CWE-Other
CVE-2005-1705 2017-10-11 10:30 2005-05-24 Show GitHub Exploit DB Packet Storm
345922 - net-snmp net-snmp fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files … NVD-CWE-Other
CVE-2005-1740 2017-10-11 10:30 2005-05-24 Show GitHub Exploit DB Packet Storm
345923 - redhat sysreport
enterprise_linux
enterprise_linux_desktop
linux_advanced_workstation
sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. NVD-CWE-Other
CVE-2005-1760 2017-10-11 10:30 2005-06-13 Show GitHub Exploit DB Packet Storm
345924 - realnetworks realplayer Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code … NVD-CWE-Other
CVE-2005-1766 2017-10-11 10:30 2005-06-28 Show GitHub Exploit DB Packet Storm
345925 - linux linux_kernel Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and poss… NVD-CWE-Other
CVE-2005-1768 2017-10-11 10:30 2005-07-11 Show GitHub Exploit DB Packet Storm
345926 - squirrelmail squirrelmail Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) … NVD-CWE-Other
CVE-2005-1769 2017-10-11 10:30 2005-06-16 Show GitHub Exploit DB Packet Storm
345927 - ekg
kde
centericq
kadu
ekg
kde
centericq
kadu
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service … CWE-189
Numeric Errors
CVE-2005-1852 2017-10-11 10:30 2005-07-26 Show GitHub Exploit DB Packet Storm
345928 - mozilla firefox
mozilla
A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerab… NVD-CWE-Other
CVE-2005-1937 2017-10-11 10:30 2005-06-14 Show GitHub Exploit DB Packet Storm
345929 - yukihiro_matsumoto ruby The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary c… NVD-CWE-Other
CVE-2005-1992 2017-10-11 10:30 2005-06-20 Show GitHub Exploit DB Packet Storm
345930 - active_web_softwares activebuyandsell Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administra… NVD-CWE-Other
CVE-2005-2062 2017-10-11 10:30 2005-06-29 Show GitHub Exploit DB Packet Storm