Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190381 7.5 重要
Network
VulcanJS - TelescopeJS における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2015-3454 2017-09-27 16:32 2015-03-25 Show GitHub Exploit DB Packet Storm
190382 7.5 重要
Network
FlightGear - FlightGear における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-13709 2017-09-27 16:25 2017-08-26 Show GitHub Exploit DB Packet Storm
190383 5.4 警告
Network
Paessler AG - Paessler PRTG Network Monitor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-12879 2017-09-27 16:25 2017-08-18 Show GitHub Exploit DB Packet Storm
190384 5.5 警告
Local
PHP-FPM - PHP-FPM におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2015-3211 2017-09-27 16:25 2015-06-5 Show GitHub Exploit DB Packet Storm
190385 7.5 重要
Network
High Availability Linux Project - ha におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2015-1198 2017-09-27 16:25 2015-01-9 Show GitHub Exploit DB Packet Storm
190386 6.1 警告
Network
Cit-e-Net - Cit-e-Net Cit-e-Access におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8753 2017-09-27 16:25 2014-10-13 Show GitHub Exploit DB Packet Storm
190387 7.8 重要
Local
シマンテック - Symantec VIP Access for Desktop におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-6329 2017-09-27 16:19 2017-08-21 Show GitHub Exploit DB Packet Storm
190388 7.8 重要
Local
Lenovo - 複数の Lenovo ThinkPad 製品における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-3756 2017-09-27 16:19 2017-08-10 Show GitHub Exploit DB Packet Storm
190389 5.5 警告
Local
MulticoreWare Inc. - MulticoreWare x265 における整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2017-13666 2017-09-27 16:19 2017-08-23 Show GitHub Exploit DB Packet Storm
190390 6.8 警告
Physics
Thales e-Security - Thales nShield Connect における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-1878 2017-09-27 16:19 2015-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
251 5.9 MEDIUM
Network
- - Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing … Update CWE-295
Improper Certificate Validation 
CVE-2026-48249 2026-05-26 23:16 2026-05-22 Show GitHub Exploit DB Packet Storm
252 5.9 MEDIUM
Network
- - Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound H… Update CWE-295
Improper Certificate Validation 
CVE-2026-48248 2026-05-26 23:16 2026-05-22 Show GitHub Exploit DB Packet Storm
253 4.1 MEDIUM
Network
- - When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Comp… New CWE-89
SQL Injection
CVE-2026-48136 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
254 5.3 MEDIUM
Network
- - A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. New CWE-122
Heap-based Buffer Overflow
CVE-2026-48135 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
255 7.5 HIGH
Network
- - When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-48133 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
256 8.1 HIGH
Network
- - The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, r… New CWE-122
Heap-based Buffer Overflow
CVE-2026-48131 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
257 6.5 MEDIUM
Network
- - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS.… New CWE-125
CWE-476
Out-of-bounds Read
 NULL Pointer Dereference
CVE-2026-41069 2026-05-26 23:16 2026-05-23 Show GitHub Exploit DB Packet Storm
258 7.1 HIGH
Network
- - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. Whil… New CWE-284
CWE-522
CWE-639
Improper Access Control
 Insufficiently Protected Credentials
 Authorization Bypass Through User-Controlled Key
CVE-2026-39968 2026-05-26 23:16 2026-05-23 Show GitHub Exploit DB Packet Storm
259 7.5 HIGH
Network
- - An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attack… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2025-11482 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
260 9.8 CRITICAL
Network
- - Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers ca… New CWE-94
Code Injection
CVE-2018-25357 2026-05-26 23:16 2026-05-24 Show GitHub Exploit DB Packet Storm