Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
361 7.8 重要
Local
Elixir-ecto Postgrex Elixir-ectoのPostgrexにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-32687 2026-05-25 10:25 2026-05-12 Show GitHub Exploit DB Packet Storm
362 7.5 重要
Network
マイクロソフト go-ntlmssp マイクロソフトのgo-ntlmsspにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-32952 2026-05-25 10:25 2026-04-24 Show GitHub Exploit DB Packet Storm
363 7.5 重要
Network
Mtrudel Bandit MtrudelのBanditにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-39803 2026-05-25 10:25 2026-05-13 Show GitHub Exploit DB Packet Storm
364 7.5 重要
Network
Mtrudel Bandit MtrudelのBanditにおける無限ループに関する脆弱性 CWE-835
無限ループ
CVE-2026-39806 2026-05-25 10:25 2026-05-13 Show GitHub Exploit DB Packet Storm
365 7.5 重要
Network
Quarkiverse Hub Quarkus OpenAPI Generator Quarkiverse HubのQuarkus OpenAPI Generatorにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40180 2026-05-25 10:25 2026-04-10 Show GitHub Exploit DB Packet Storm
366 8.8 重要
Network
OWASP OWASP BLT OWASPのOWASP BLTにおける複数の脆弱性 CWE-94
CWE-95
CVE-2026-40316 2026-05-25 10:25 2026-04-15 Show GitHub Exploit DB Packet Storm
367 7.5 重要
Network
WebOnyx graphql-php WebOnyxのgraphql-phpにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-40476 2026-05-25 10:25 2026-04-17 Show GitHub Exploit DB Packet Storm
368 5.9 警告
Network
Jeffrey Stedfast (jstedfast) MailKit Jeffrey Stedfast (jstedfast)のMailKitにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-41319 2026-05-25 10:25 2026-04-24 Show GitHub Exploit DB Packet Storm
369 9.8 緊急
Network
pgx project pgx JackcのpgxにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-41889 2026-05-25 10:25 2026-05-8 Show GitHub Exploit DB Packet Storm
370 5.4 警告
Network
reconurge Flowsint Flowsintにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42159 2026-05-25 10:25 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318951 - phorum phorum SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report, st… NVD-CWE-Other
CVE-2006-3249 2024-08-8 04:15 2006-06-27 Show GitHub Exploit DB Packet Storm
318952 - nucleus_group nucleus_cms Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/n… CWE-94
Code Injection
CVE-2006-3136 2024-08-8 04:15 2006-06-23 Show GitHub Exploit DB Packet Storm
318953 - iglooweb doublespeak PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files… NVD-CWE-Other
CVE-2006-3069 2024-08-8 04:15 2006-06-19 Show GitHub Exploit DB Packet Storm
318954 - phorum phorum PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. NOTE: this issu… NVD-CWE-Other
CVE-2006-3053 2024-08-8 04:15 2006-06-16 Show GitHub Exploit DB Packet Storm
318955 - amr_talkbox amr_talkbox PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by C… NVD-CWE-Other
CVE-2006-3040 2024-08-8 04:15 2006-06-15 Show GitHub Exploit DB Packet Storm
318956 - codewalkers ltwcalendar PHP remote file inclusion vulnerability in Ltwcalendar/calendar.php in Codewalkers Ltwcalendar 4.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the ltw_config[include_dir] par… NVD-CWE-Other
CVE-2006-3041 2024-08-8 04:15 2006-06-15 Show GitHub Exploit DB Packet Storm
318957 - ispconfig ispconfig Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.… NVD-CWE-Other
CVE-2006-3042 2024-08-8 04:15 2006-06-15 Show GitHub Exploit DB Packet Storm
318958 9.8 CRITICAL
Network
oretnom23 simple_realtime_quiz_system A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component … CWE-89
SQL Injection
CVE-2024-7369 2024-08-8 04:03 2024-08-2 Show GitHub Exploit DB Packet Storm
318959 5.4 MEDIUM
Network
oretnom23 simple_realtime_quiz_system A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The man… CWE-79
Cross-site Scripting
CVE-2024-7368 2024-08-8 04:03 2024-08-2 Show GitHub Exploit DB Packet Storm
318960 8.8 HIGH
Network
oretnom23 simple_realtime_quiz_system A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the … CWE-89
SQL Injection
CVE-2024-7370 2024-08-8 03:51 2024-08-2 Show GitHub Exploit DB Packet Storm