Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
101 8.2 重要
Network
VMware Spring AI VMwareのSpring AIにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 New CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-41713 2026-05-14 10:18 2026-05-12 Show GitHub Exploit DB Packet Storm
102 6.5 警告
Network
LangGenius Dify LangGeniusのDifyにおけるユーザ制御の鍵による認証回避に関する脆弱性 New CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41950 2026-05-14 10:18 2026-05-5 Show GitHub Exploit DB Packet Storm
103 9.6 緊急
Network
Streetwriters Notesnook Mobile
Notesnook Desktop
StreetwritersのNotesnook Desktop等の複数製品における複数の脆弱性 New CWE-79
CWE-94
CVE-2026-42090 2026-05-14 10:18 2026-05-4 Show GitHub Exploit DB Packet Storm
104 6.5 警告
Network
goshs goshs goshsにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-42091 2026-05-14 10:18 2026-05-4 Show GitHub Exploit DB Packet Storm
105 4.8 警告
Network
Weblate wlc Weblateのwlcにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42150 2026-05-14 10:18 2026-05-8 Show GitHub Exploit DB Packet Storm
106 5.9 警告
Network
Teluu Ltd. PJSIP Teluu Ltd.のPJSIPにおける証明書検証に関する脆弱性 New CWE-295
不正な証明書検証
CVE-2026-42225 2026-05-14 10:18 2026-05-7 Show GitHub Exploit DB Packet Storm
107 4.3 警告
Network
Onyx Onyx Onyxにおけるユーザ制御の鍵による認証回避に関する脆弱性 New CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-42276 2026-05-14 10:18 2026-05-8 Show GitHub Exploit DB Packet Storm
108 6.5 警告
Network
Onyx Onyx Onyxにおけるユーザ制御の鍵による認証回避に関する脆弱性 New CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-42277 2026-05-14 10:18 2026-05-8 Show GitHub Exploit DB Packet Storm
109 5.5 警告
Local
Python Software Foundation Python Pillow Python Software FoundationのPython Pillowにおける整数オーバーフローの脆弱性 New CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-42308 2026-05-14 10:18 2026-05-9 Show GitHub Exploit DB Packet Storm
110 5.5 警告
Local
Python Software Foundation Python Pillow Python Software FoundationのPython Pillowにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-42309 2026-05-14 10:18 2026-05-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346721 - hp jetadmin HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file. NVD-CWE-Other
CVE-1999-1433 2016-10-18 11:04 1998-07-15 Show GitHub Exploit DB Packet Storm
346722 - slackware slackware_linux login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to … NVD-CWE-Other
CVE-1999-1434 2016-10-18 11:04 1998-07-13 Show GitHub Exploit DB Packet Storm
346723 - nec socks_5 Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables. NVD-CWE-Other
CVE-1999-1435 2016-10-18 11:04 1998-07-10 Show GitHub Exploit DB Packet Storm
346724 - ray_chan www_authorization_gateway Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter. NVD-CWE-Other
CVE-1999-1436 2016-10-18 11:04 1998-07-8 Show GitHub Exploit DB Packet Storm
346725 - ralf_s._engelschall eperl ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml. NVD-CWE-Other
CVE-1999-1437 2016-10-18 11:04 1998-07-7 Show GitHub Exploit DB Packet Storm
346726 - gcc gcc gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files. NVD-CWE-Other
CVE-1999-1439 2016-10-18 11:04 1998-01-2 Show GitHub Exploit DB Packet Storm
346727 - mirabilis icq_98a Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many s… NVD-CWE-Other
CVE-1999-1440 2016-10-18 11:04 1999-01-1 Show GitHub Exploit DB Packet Storm
346728 - linux linux_kernel Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch i… NVD-CWE-Other
CVE-1999-1441 2016-10-18 11:04 1998-06-30 Show GitHub Exploit DB Packet Storm
346729 - micah_software full_armor Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using <CTRL><ALT><DEL> and kill the process using… NVD-CWE-Other
CVE-1999-1443 2016-10-18 11:04 1998-06-2 Show GitHub Exploit DB Packet Storm
346730 - slackware slackware_linux Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and … NVD-CWE-Other
CVE-1999-1445 2016-10-18 11:04 1998-02-2 Show GitHub Exploit DB Packet Storm