Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4681 6.5 警告
Network
マイクロソフト Microsoft Teams Microsoft Team Events Portal Information Disclosure Vulnerability CWE-285
不適切な認可
CVE-2026-33823 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4682 9 緊急
Network
マイクロソフト Azure Managed Instance for Apache Cassandra Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability CWE-20
不適切な入力確認
CVE-2026-33844 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4683 8.2 重要
Network
マイクロソフト Microsoft Partner Center Microsoft Partner Center Spoofing Vulnerability CWE-610
別領域リソースに対する外部からの制御可能な参照
CVE-2026-34327 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4684 5.3 警告
Network
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける弱いハッシュの使用に関する脆弱性 CWE-328
脆弱なハッシュの使用
CVE-2026-34527 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
4685 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35072 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
4686 6.7 警告
Local
デル data domain operating system デルのdata domain operating systemにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35073 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
4687 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35074 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
4688 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品における引数の挿入または変更に関する脆弱性 CWE-88
引数の挿入または変更
CVE-2026-35153 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
4689 8.8 重要
Network
Project Jupyter Jupyter Server Project JupyterのJupyter Serverにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-35397 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
4690 9.6 緊急
Network
マイクロソフト Azure Cloud Shell Azure Cloud Shell Spoofing Vulnerability CWE-77
コマンドインジェクション
CVE-2026-35428 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349511 - lucidcms lucidcms LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message. NVD-CWE-Other
CVE-2006-1635 2017-07-20 10:30 2006-04-6 Show GitHub Exploit DB Packet Storm
349512 - interact interact Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and (2) the first_name,… NVD-CWE-Other
CVE-2006-1642 2017-07-20 10:30 2006-04-6 Show GitHub Exploit DB Packet Storm
349513 - interact interact SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_name parameter. NOTE: the provenance of this information is unknown;… NVD-CWE-Other
CVE-2006-1643 2017-07-20 10:30 2006-04-6 Show GitHub Exploit DB Packet Storm
349514 - interact interact login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames. NOTE: the provenance of this in… NVD-CWE-Other
CVE-2006-1644 2017-07-20 10:30 2006-04-6 Show GitHub Exploit DB Packet Storm
349515 - sk_soft skforum Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time… NVD-CWE-Other
CVE-2006-1661 2017-07-20 10:30 2006-04-7 Show GitHub Exploit DB Packet Storm
349516 - jelsoft vbug_tracker Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter. NVD-CWE-Other
CVE-2006-1673 2017-07-20 10:30 2006-04-7 Show GitHub Exploit DB Packet Storm
349517 - phpmyadmin phpmyadmin Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes… NVD-CWE-Other
CVE-2006-1678 2017-07-20 10:30 2006-04-11 Show GitHub Exploit DB Packet Storm
349518 - talentsoft web\+_shop Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly invo… NVD-CWE-Other
CVE-2006-1682 2017-07-20 10:30 2006-04-11 Show GitHub Exploit DB Packet Storm
349519 - apt apt-webshop-system Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, an… NVD-CWE-Other
CVE-2006-1685 2017-07-20 10:30 2006-04-11 Show GitHub Exploit DB Packet Storm
349520 - manic_web mwnewsletter Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter. NVD-CWE-Other
CVE-2006-1690 2017-07-20 10:30 2006-04-11 Show GitHub Exploit DB Packet Storm