Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191491 10 緊急
Network
Hangzhou Hikvision Digital Technology - 複数の Hikvision 製品における認証に関する脆弱性 CWE-287
不適切な認証
CVE-2017-7921 2017-07-13 15:02 2017-03-10 Show GitHub Exploit DB Packet Storm
191492 5.5 警告
Local
AudioCoding - Freeware Advanced Audio Coder の libfaac/frame.c の faacEncOpen 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2017-9130 2017-07-13 14:57 2017-06-20 Show GitHub Exploit DB Packet Storm
191493 5.3 警告
Network
IBM - IBM WebSphere MQ の MQXR チャネルにおけるサービス運用妨害 (DoS) の脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-1117 2017-07-13 14:48 2017-06-6 Show GitHub Exploit DB Packet Storm
191494 9.1 緊急
Network
MatrixSSL project - InsideSecure MatrixSSL における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2017-2782 2017-07-13 13:53 2017-06-22 Show GitHub Exploit DB Packet Storm
191495 9.8 緊急
Network
MatrixSSL project - InsideSecure MatrixSSL におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-2781 2017-07-13 13:53 2017-06-22 Show GitHub Exploit DB Packet Storm
191496 9.8 緊急
Network
MatrixSSL project - InsideSecure MatrixSSL におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-2780 2017-07-13 13:53 2017-06-22 Show GitHub Exploit DB Packet Storm
191497 9.8 緊急
Network
NetBSD - NetBSD におけるリソース管理に関する脆弱性 CWE-399
リソース管理の問題
CVE-2017-1000378 2017-07-13 11:55 2017-05-19 Show GitHub Exploit DB Packet Storm
191498 9.8 緊急
Network
NetBSD - NetBSD におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-1000375 2017-07-13 11:55 2017-06-19 Show GitHub Exploit DB Packet Storm
191499 9.8 緊急
Network
NetBSD - NetBSD のスタックガードページの実装におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-1000374 2017-07-13 11:55 2017-06-19 Show GitHub Exploit DB Packet Storm
191500 9.8 緊急
Network
OpenBSD - OpenBSD のスタックガードページの実装におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-1000372 2017-07-13 11:55 2017-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 8.6 HIGH
Network
- - 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object… New CWE-22
CWE-1321
Path Traversal
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-41690 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
412 8.6 HIGH
Network
- - i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled languag… New CWE-79
CWE-113
Cross-site Scripting
HTTP Response Splitting
CVE-2026-41683 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
413 6.4 MEDIUM
Network
- - Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style… New CWE-79
Cross-site Scripting
CVE-2026-41591 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
414 10.0 CRITICAL
Network
- - openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth… New CWE-287
Improper Authentication
CVE-2026-41070 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
415 6.3 MEDIUM
Network
- - In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), da… New CWE-282
 Improper Ownership Management
CVE-2026-40214 2026-05-9 01:16 2026-05-8 Show GitHub Exploit DB Packet Storm
416 7.4 HIGH
Network
- - OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless… New CWE-863
 Incorrect Authorization
CVE-2026-40213 2026-05-9 01:16 2026-05-8 Show GitHub Exploit DB Packet Storm
417 7.4 HIGH
Local
- - Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo… New CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-34354 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
418 - - - lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by o… New - CVE-2026-29975 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
419 - - - An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided buffer without a size parameter. Applications using minmea_scan o… New - CVE-2026-29974 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
420 8.6 HIGH
Network
- - Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows un… New CWE-200
CWE-497
Information Exposure
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-42047 2026-05-9 01:08 2026-05-8 Show GitHub Exploit DB Packet Storm