Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190321 6.1 警告
Network
OSNEXUS Corporation - OSNEXUS QuantaStor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-9979 2017-09-28 17:30 2017-08-12 Show GitHub Exploit DB Packet Storm
190322 5.3 警告
Network
OSNEXUS Corporation - OSNEXUS QuantaStor における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2017-9978 2017-09-28 17:30 2017-08-12 Show GitHub Exploit DB Packet Storm
190323 7.5 重要
Network
Heimdal
openSUSE project
- Heimdal におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-6594 2017-09-28 17:30 2017-04-14 Show GitHub Exploit DB Packet Storm
190324 6.1 警告
Network
IBM - IBM Security Access Manager におけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2017-1489 2017-09-28 17:30 2017-08-4 Show GitHub Exploit DB Packet Storm
190325 9.8 緊急
Network
Linux - Linux Kernel における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-13715 2017-09-28 17:30 2017-08-24 Show GitHub Exploit DB Packet Storm
190326 8.8 重要
Network
Huawei - Huawei Video Content Management における認証に関する脆弱性 CWE-287
不適切な認証
CVE-2015-8332 2017-09-28 17:30 2015-11-25 Show GitHub Exploit DB Packet Storm
190327 7.8 重要
Local
コーレル株式会社 - 複数の Corel 製品における制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2014-8393 2017-09-28 17:30 2014-12-9 Show GitHub Exploit DB Packet Storm
190328 7 重要
Local
BitDefender - Bitdefender Total Security における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-10950 2017-09-28 17:26 2017-08-17 Show GitHub Exploit DB Packet Storm
190329 8.8 重要
Network
Foxit Software Inc - Foxit Reader における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-10952 2017-09-28 17:21 2017-08-17 Show GitHub Exploit DB Packet Storm
190330 8.8 重要
Network
Foxit Software Inc - Foxit Reader におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-10951 2017-09-28 17:21 2017-08-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
391 8.5 HIGH
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.Th… New CWE-89
SQL Injection
CVE-2026-42730 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
392 9.8 CRITICAL
Network
- - Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a… New CWE-266
 Incorrect Privilege Assignment
CVE-2026-42731 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
393 6.5 MEDIUM
Network
- - Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Input Data Manipulation.This issue affects Ads by WPQuads: from n/a thr… New CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-42732 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
394 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through … New CWE-79
Cross-site Scripting
CVE-2026-42733 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
395 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Reflected XSS.This issue affects Geo Mashup: from n/a t… New CWE-79
Cross-site Scripting
CVE-2026-42734 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
396 8.2 HIGH
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: f… New CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42735 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
397 7.5 HIGH
Network
- - Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-42736 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
398 8.6 HIGH
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikB… New CWE-22
Path Traversal
CVE-2026-42737 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
399 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects S… New CWE-79
Cross-site Scripting
CVE-2026-42738 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
400 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced … New CWE-79
Cross-site Scripting
CVE-2026-42739 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm