Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190431 9.1 緊急
Network
日本電気
Apache Software Foundation
- Apache HTTP Server における入力確認に関する脆弱性 CWE-20
CWE-200
CVE-2017-9788 2017-10-3 12:27 2017-07-11 Show GitHub Exploit DB Packet Storm
190432 7.5 重要
Network
日本電気
Apache Software Foundation
- Apache Tomcat におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2017-7675 2017-10-3 12:27 2017-08-11 Show GitHub Exploit DB Packet Storm
190433 8.1 重要
Network
マイクロソフト
日立
- 複数の Microsoft Windows 製品の Windows NetBT セッションサービスコンポーネントにおけるリモートでコードを実行される脆弱性 CWE-200
情報漏えい
CVE-2017-0161 2017-10-3 12:27 2017-09-12 Show GitHub Exploit DB Packet Storm
190434 6.1 警告
Network
NexusPHP project - NexusPHP におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-12906 2017-10-2 18:08 2017-09-7 Show GitHub Exploit DB Packet Storm
190435 8.8 重要
Network
NexusPHP project - NexusPHP におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-12838 2017-10-2 18:08 2017-09-7 Show GitHub Exploit DB Packet Storm
190436 7.5 重要
Network
LibGD project
Debian
Canonical
Fedora Project
- libgd2 における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2017-6362 2017-10-2 18:07 2017-08-30 Show GitHub Exploit DB Packet Storm
190437 6.1 警告
Local
TUG - texlive パッケージの mktexlsr におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2015-5701 2017-10-2 17:59 2015-01-12 Show GitHub Exploit DB Packet Storm
190438 6.1 警告
Local
TUG - texlive パッケージの mktexlsr におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2015-5700 2017-10-2 17:59 2015-01-12 Show GitHub Exploit DB Packet Storm
190439 7.8 重要
Local
STDUtility - STDU Viewer におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-14293 2017-10-2 17:04 2017-09-11 Show GitHub Exploit DB Packet Storm
190440 7.8 重要
Local
STDUtility - STDU Viewer におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-14292 2017-10-2 17:04 2017-09-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
821 6.5 MEDIUM
Network
- - Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int… New CWE-22
Path Traversal
CVE-2026-41863 2026-05-27 05:16 2026-05-25 Show GitHub Exploit DB Packet Storm
822 3.3 LOW
Local
- - A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of t… New CWE-401
CWE-404
 Missing Release of Memory after Effective Lifetime
 Improper Resource Shutdown or Release
CVE-2026-9572 2026-05-27 05:16 2026-05-27 Show GitHub Exploit DB Packet Storm
823 8.2 HIGH
Network
- - code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-8890 2026-05-27 05:16 2026-05-27 Show GitHub Exploit DB Packet Storm
824 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid… New - CVE-2026-8453 2026-05-27 05:16 2026-05-27 Show GitHub Exploit DB Packet Storm
825 3.1 LOW
Network
- - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user a… New CWE-639
CWE-862
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
CVE-2026-39967 2026-05-27 05:16 2026-05-23 Show GitHub Exploit DB Packet Storm
826 - - - A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network. New CWE-79
Cross-site Scripting
CVE-2026-6059 2026-05-27 05:14 2026-05-25 Show GitHub Exploit DB Packet Storm
827 - - - An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjac… New CWE-78
OS Command 
CVE-2026-8652 2026-05-27 05:14 2026-05-25 Show GitHub Exploit DB Packet Storm
828 - - - In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_s… New - CVE-2026-43503 2026-05-27 05:06 2026-05-23 Show GitHub Exploit DB Packet Storm
829 8.5 HIGH
Network
- - A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field… New CWE-88
Argument Injection
CVE-2026-3515 2026-05-27 05:06 2026-05-24 Show GitHub Exploit DB Packet Storm
830 7.8 HIGH
Local
- - A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config… New CWE-1066
CVE-2026-4372 2026-05-27 05:06 2026-05-24 Show GitHub Exploit DB Packet Storm