Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4111 9.1 緊急
Network
Froxlor Froxlor Froxlorにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41229 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4112 8.5 重要
Network
Froxlor Froxlor FroxlorにおけるCRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2026-41230 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4113 7.5 重要
Network
Froxlor Froxlor Froxlorにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-41231 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4114 5 警告
Network
Froxlor Froxlor Froxlorにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41232 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4115 5.4 警告
Network
Froxlor Froxlor Froxlorにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41233 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4116 8.6 重要
Local
OpenClaw OpenClaw OpenClawにおけるシステム構成または設定の外部制御に関する脆弱性 CWE-15
システム構成または設定の外部制御
CVE-2026-41294 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
4117 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-41295 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
4118 8.2 重要
Network
OpenClaw OpenClaw OpenClawにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41296 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
4119 7.6 重要
Network
OpenClaw OpenClaw OpenClawにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41297 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
4120 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41298 2026-04-30 12:26 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348641 - winftp_server winftp_server WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local users to gain access to the credentials. NVD-CWE-Other
CVE-2004-2400 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348642 - ipswitch imail_express Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." NVD-CWE-Other
CVE-2004-2401 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348643 - yabb yabb Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that… NVD-CWE-Other
CVE-2004-2402 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348644 - yabb yabb Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specif… NVD-CWE-Other
CVE-2004-2403 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348645 - f-secure f-secure_anti-virus
f-secure_for_firewalls
f-secure_internet_security
internet_gatekeeper
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module rest… NVD-CWE-Other
CVE-2004-2405 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348646 - vserver linux-vserver Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to set permissions in … NVD-CWE-Other
CVE-2004-2408 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348647 - samhain_labs samhain Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t update"), might allow attackers to execute arbitrary code. NVD-CWE-Other
CVE-2004-2409 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348648 - virtual_programming vp-asp The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks t… NVD-CWE-Other
CVE-2004-2411 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348649 - virtual_programming vp-asp Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shopreviewlist.asp and (2) s… NVD-CWE-Other
CVE-2004-2412 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
348650 - virtual_programming vp-asp SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to… NVD-CWE-Other
CVE-2004-2413 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm