Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191541 9.8 緊急
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-4053 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
191542 9.8 緊急
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおける認証を回避される脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2017-4052 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
191543 7.3 重要
Local
Foxit Software Inc - Foxit Reader および PhantomPDF における任意のコードを実行される脆弱性 CWE-123
任意の場所に任意の値を書き込み可能な状態
CVE-2017-10994 2017-08-1 15:30 2017-07-4 Show GitHub Exploit DB Packet Storm
191544 6.1 警告
Network
WP Statistics - WordPress 用 WP Statistics プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-10991 2017-08-1 15:30 2017-07-7 Show GitHub Exploit DB Packet Storm
191545 9.8 緊急
Network
Irssi - Irssi における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2017-10966 2017-08-1 15:30 2017-07-5 Show GitHub Exploit DB Packet Storm
191546 7 重要
Local
Google - Android の ActivityManagerService の bindBackupAgent メソッドにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2014-7953 2017-08-1 15:30 2014-09-10 Show GitHub Exploit DB Packet Storm
191547 7.5 重要
Network
Schneider Electric - Schneider Electric Wonderware ArchestrA Logger における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-9631 2017-08-1 13:58 2017-06-30 Show GitHub Exploit DB Packet Storm
191548 9.8 緊急
Network
Schneider Electric - Schneider Electric Wonderware ArchestrA Logger におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-9629 2017-08-1 13:58 2017-06-30 Show GitHub Exploit DB Packet Storm
191549 8.6 重要
Network
Schneider Electric - Schneider Electric Wonderware ArchestrA Logger におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2017-9627 2017-08-1 13:58 2017-06-30 Show GitHub Exploit DB Packet Storm
191550 9.8 緊急
Network
Irssi - Irssi における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-10965 2017-08-1 12:11 2017-07-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1241 - - - The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development fea… CWE-297
CWE-322
 Improper Validation of Certificate with Host Mismatch
 Key Exchange without Entity Authentication
CVE-2026-44467 2026-05-14 01:58 2026-05-14 Show GitHub Exploit DB Packet Storm
1242 - - - The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Window… CWE-59
CWE-269
Link Following
 Improper Privilege Management
CVE-2026-44470 2026-05-14 01:58 2026-05-14 Show GitHub Exploit DB Packet Storm
1243 5.5 MEDIUM
Local
- - Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), comma… CWE-200
CWE-532
Information Exposure
 Inclusion of Sensitive Information in Log Files
CVE-2026-44479 2026-05-14 01:58 2026-05-14 Show GitHub Exploit DB Packet Storm
1244 9.1 CRITICAL
Network
- - auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the … CWE-287
Improper Authentication
CVE-2026-42560 2026-05-14 01:58 2026-05-9 Show GitHub Exploit DB Packet Storm
1245 8.8 HIGH
Network
- - OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_ta… CWE-94
CWE-95
Code Injection
Eval Injection
CVE-2026-42603 2026-05-14 01:58 2026-05-12 Show GitHub Exploit DB Packet Storm
1246 - - - Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach t… CWE-120
Classic Buffer Overflow
CVE-2026-42859 2026-05-14 01:58 2026-05-12 Show GitHub Exploit DB Packet Storm
1247 6.1 MEDIUM
Network
- - fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values contain… CWE-91
Blind XPath Injection
CVE-2026-44664 2026-05-14 01:58 2026-05-14 Show GitHub Exploit DB Packet Storm
1248 - - - New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-591… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42339 2026-05-14 01:53 2026-05-9 Show GitHub Exploit DB Packet Storm
1249 6.5 MEDIUM
Network
- - kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the k… CWE-943
 Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-42316 2026-05-14 01:53 2026-05-12 Show GitHub Exploit DB Packet Storm
1250 6.1 MEDIUM
Network
- - fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. T… CWE-91
Blind XPath Injection
CVE-2026-44665 2026-05-14 01:53 2026-05-14 Show GitHub Exploit DB Packet Storm