Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 10:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5351 5.4 警告
Network
spomky-labs webauthn-lib
webauthn-symfony-bundle
webauthn framwork
spomky-labsのwebauthn-lib等の複数製品における同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-30964 2026-05-11 11:02 2026-03-10 Show GitHub Exploit DB Packet Storm
5352 6.5 警告
Network
appium Appium/support appiumのAppium/supportにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-30973 2026-05-11 11:02 2026-03-10 Show GitHub Exploit DB Packet Storm
5353 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows Server 2022
Microsoft Windows 11 24h2
Microsoft Windows 11 25h2
Microsoft …
リモート デスクトップ クライアントのリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32157 2026-05-11 11:02 2026-04-14 Show GitHub Exploit DB Packet Storm
5354 10 緊急
Network
Luis Novo (lfnovo) Open Notebook Luis Novo (lfnovo)のOpen Notebookにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-33587 2026-05-11 11:02 2026-05-7 Show GitHub Exploit DB Packet Storm
5355 8.1 重要
Network
Luis Novo (lfnovo) Open Notebook Luis Novo (lfnovo)のOpen Notebookにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-33588 2026-05-11 11:02 2026-05-7 Show GitHub Exploit DB Packet Storm
5356 6.5 警告
Network
Luis Novo (lfnovo) Open Notebook Luis Novo (lfnovo)のOpen Notebookにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-33589 2026-05-11 11:02 2026-05-7 Show GitHub Exploit DB Packet Storm
5357 9.8 緊急
Network
bukts.ru LLC (Nefteprodukttekhnika) BUK TS-G Gas Station Automation System bukts.ru LLC (Nefteprodukttekhnika)のBUK TS-G Gas Station Automation SystemにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-3843 2026-05-11 11:02 2026-03-10 Show GitHub Exploit DB Packet Storm
5358 6.1 警告
Network
spin.js spin.js spin.jsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-3884 2026-05-11 11:02 2026-03-11 Show GitHub Exploit DB Packet Storm
5359 8.3 重要
Network
HCL Technologies Limited HCL BigFix Service Management (SM) HCL Technologies LimitedのHCL BigFix Service Management (SM)におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2024-30151 2026-05-11 11:02 2026-05-6 Show GitHub Exploit DB Packet Storm
5360 5.7 警告
Network
HCL Technologies Limited HCL BigFix Service Management (SM) HCL Technologies LimitedのHCL BigFix Service Management (SM)におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2025-31957 2026-05-11 11:02 2026-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
350311 - alstrasoft affiliate_network_pro Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php … NVD-CWE-Other
CVE-2005-3795 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350312 - alstrasoft affiliate_network_pro Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute arbitrary PHP code via the number parameter. NOTE: it is no… NVD-CWE-Other
CVE-2005-3796 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350313 - alstrasoft template_seller PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter. NVD-CWE-Other
CVE-2005-3797 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350314 - alstrasoft template_seller SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field. NVD-CWE-Other
CVE-2005-3798 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350315 - - - Macromedia Contribute Publishing Server (CPS) before 1.11 uses a weak algorithm to encrypt user password in connection keys that use shared FTP login credentials, which allows attackers to obtain sen… NVD-CWE-Other
CVE-2005-3800 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350316 - cisco 7920_wireless_ip_phone Cisco IP Phone (VoIP) 7920 1.0(8) listens to UDP port 17185 to support a VxWorks debugger, which allows remote attackers to obtain sensitive information and cause a denial of service. NVD-CWE-Other
CVE-2005-3804 2017-07-11 10:33 2005-11-24 Show GitHub Exploit DB Packet Storm
350317 - amax_information_technologies magic_winmail_server Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid… NVD-CWE-Other
CVE-2005-3811 2017-07-11 10:33 2005-11-26 Show GitHub Exploit DB Packet Storm
350318 - softbiz web_hosting_directory_script Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2… CWE-89
SQL Injection
CVE-2005-3817 2017-07-11 10:33 2005-11-26 Show GitHub Exploit DB Packet Storm
350319 - nicecoder idesk SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NVD-CWE-Other
CVE-2005-3843 2017-07-11 10:33 2005-11-27 Show GitHub Exploit DB Packet Storm
350320 - ezinvoiceinc ez_invoice_inc SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a pa… CWE-89
SQL Injection
CVE-2005-3845 2017-07-11 10:33 2005-11-27 Show GitHub Exploit DB Packet Storm