Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191411 7.8 重要
Local
Artifex Software - Artifex Ghostscript GhostXPS におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-9611 2017-09-1 15:52 2017-06-13 Show GitHub Exploit DB Packet Storm
191412 7.8 重要
Local
Artifex Software - Artifex Ghostscript GhostXPS におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-9610 2017-09-1 15:52 2017-06-13 Show GitHub Exploit DB Packet Storm
191413 8.8 重要
Network
OpenCV team - OpenCV における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2017-12599 2017-09-1 15:38 2017-08-23 Show GitHub Exploit DB Packet Storm
191414 8.8 重要
Network
OpenCV team - OpenCV における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2017-12598 2017-09-1 15:38 2017-08-23 Show GitHub Exploit DB Packet Storm
191415 8.8 重要
Network
OpenCV team - OpenCV における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2017-12597 2017-09-1 15:38 2017-08-23 Show GitHub Exploit DB Packet Storm
191416 6.5 警告
Local
NVIDIA - NVIDIA Windows GPU Display Driver におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-6260 2017-09-1 14:38 2017-07-24 Show GitHub Exploit DB Packet Storm
191417 6.1 警告
Network
NVIDIA - NVIDIA GPU Display Driver における脆弱性 CWE-noinfo
情報不足
CVE-2017-6259 2017-09-1 14:38 2017-07-24 Show GitHub Exploit DB Packet Storm
191418 8.8 重要
Local
NVIDIA - NVIDIA GPU Display Driver における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-6257 2017-09-1 14:38 2017-07-24 Show GitHub Exploit DB Packet Storm
191419 5.3 警告
Network
MantisBT Group - MantisBT における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2015-5059 2017-09-1 13:52 2015-06-24 Show GitHub Exploit DB Packet Storm
191420 5.5 警告
Local
divfix - DivFix++ における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2017-11330 2017-09-1 13:52 2017-07-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1511 6.5 MEDIUM
Network
hcltech bigfix_webui_api
bigfix_webui_application_administration
bigfix_webui_cmep
bigfix_webui_common
bigfix_webui_content_app
bigfix_webui_custom
bigfix_webui_data_sync
bigfix_webui_ex…
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)… CWE-863
 Incorrect Authorization
CVE-2025-15633 2026-05-15 05:28 2026-05-9 Show GitHub Exploit DB Packet Storm
1512 4.3 MEDIUM
Network
hcltech bigfix_webui_api
bigfix_webui_application_administration
bigfix_webui_cmep
bigfix_webui_common
bigfix_webui_content_app
bigfix_webui_custom
bigfix_webui_data_sync
bigfix_webui_ex…
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized… CWE-862
 Missing Authorization
CVE-2025-15634 2026-05-15 05:28 2026-05-9 Show GitHub Exploit DB Packet Storm
1513 7.8 HIGH
Local
python pillow Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e… CWE-190
CWE-787
 Integer Overflow or Wraparound
 Out-of-bounds Write
CVE-2026-42311 2026-05-15 05:27 2026-05-9 Show GitHub Exploit DB Packet Storm
1514 7.6 HIGH
Network
- - Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted… CWE-22
Path Traversal
CVE-2026-45225 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1515 8.2 HIGH
Network
- - Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42260 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1516 7.3 HIGH
Network
- - An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-37430 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1517 7.5 HIGH
Network
- - The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expos… CWE-306
Missing Authentication for Critical Function
CVE-2026-31240 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1518 9.8 CRITICAL
Network
- - The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method u… CWE-502
 Deserialization of Untrusted Data
CVE-2026-31239 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1519 9.8 CRITICAL
Network
- - The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads mo… CWE-502
 Deserialization of Untrusted Data
CVE-2026-31238 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm
1520 9.8 CRITICAL
Network
- - The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework auto… CWE-502
 Deserialization of Untrusted Data
CVE-2026-31237 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm