Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191091 9.8 緊急
Network
マイクロソフト - Microsoft ChakraCore におけるリモートでコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2017-8658 2017-09-12 11:51 2017-08-10 Show GitHub Exploit DB Packet Storm
191092 8.1 重要
Network
Tune Library project - WordPress 用 Tune Library プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-3314 2017-09-12 11:32 2015-04-20 Show GitHub Exploit DB Packet Storm
191093 9.8 緊急
Network
Community Events project - WordPress 用 Community Events プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-3313 2017-09-12 11:32 2015-04-18 Show GitHub Exploit DB Packet Storm
191094 7.5 重要
Network
Apache Software Foundation - Apache Struts 2 における Struts 内部を操作される脆弱性 CWE-20
不適切な入力確認
CVE-2015-5209 2017-09-12 11:28 2015-10-21 Show GitHub Exploit DB Packet Storm
191095 6.1 警告
Network
Broken Link Checker project - Wordpress 用 Broken Link Checker プラグインの Wordpress 管理パネルにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-5057 2017-09-11 18:34 2015-06-24 Show GitHub Exploit DB Packet Storm
191096 6.1 警告
Network
PHPMyWind.COM - PHPMyWind におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-12984 2017-09-11 18:07 2017-08-21 Show GitHub Exploit DB Packet Storm
191097 8.8 重要
Network
ImageMagick - ImageMagick におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-12983 2017-09-11 18:07 2017-08-18 Show GitHub Exploit DB Packet Storm
191098 8.8 重要
Network
Podlove - WordPress 用 Podlove Podcast Publisher プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-12949 2017-09-11 18:06 2017-08-7 Show GitHub Exploit DB Packet Storm
191099 6.1 警告
Network
PressForward - WordPress 用 PressForward プラグインの Core\Admin\PFTemplater.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-12948 2017-09-11 17:11 2017-08-7 Show GitHub Exploit DB Packet Storm
191100 7.2 重要
Network
Daniel Iser - WordPress 用 Easy Modal プラグインの classes\controller\admin\modals.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-12947 2017-09-11 17:11 2017-08-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1601 6.5 MEDIUM
Network
- - A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could … CWE-121
Stack-based Buffer Overflow
CVE-2026-9150 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1602 6.5 MEDIUM
Network
- - A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. T… CWE-122
Heap-based Buffer Overflow
CVE-2026-9149 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1603 4.3 MEDIUM
Network
- - Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in… CWE-863
 Incorrect Authorization
CVE-2026-4055 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1604 6.1 MEDIUM
Network
- - Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Ma… CWE-352
 Origin Validation Error
CVE-2026-22880 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1605 8.0 HIGH
Network
- - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an… CWE-22
Path Traversal
CVE-2026-4858 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1606 8.4 HIGH
Network
- - Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent mac… CWE-77
Command Injection
CVE-2026-2740 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
1607 7.1 HIGH
Network
- - Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. Thi… CWE-359
CWE-522
 Exposure of Private Personal Information to an Unauthorized Actor
 Insufficiently Protected Credentials
CVE-2025-13477 2026-05-22 00:24 2026-05-21 Show GitHub Exploit DB Packet Storm
1608 7.5 HIGH
Network
- - Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: throug… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-13479 2026-05-22 00:24 2026-05-21 Show GitHub Exploit DB Packet Storm
1609 5.7 MEDIUM
Network
- - Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 b… CWE-613
 Insufficient Session Expiration
CVE-2026-1815 2026-05-22 00:24 2026-05-22 Show GitHub Exploit DB Packet Storm
1610 6.3 MEDIUM
Network
- - Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Appli… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-1816 2026-05-22 00:24 2026-05-22 Show GitHub Exploit DB Packet Storm