Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191651 8.8 重要
Network
シスコシステムズ - Cisco Elastic Services Controller の ConfD CLI における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2017-6682 2017-07-10 17:29 2017-06-7 Show GitHub Exploit DB Packet Storm
191652 6.1 警告
Network
シスコシステムズ - Cisco ESA および SMA の Web ベースの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6661 2017-07-10 17:29 2017-06-7 Show GitHub Exploit DB Packet Storm
191653 8.8 重要
Network
シスコシステムズ - Cisco Prime Collaboration Assurance の Web ベースの管理インターフェースにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-6659 2017-07-10 17:29 2017-06-7 Show GitHub Exploit DB Packet Storm
191654 5.4 警告
Network
IBM - IBM Jazz Foundation におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9973 2017-07-10 17:04 2016-12-16 Show GitHub Exploit DB Packet Storm
191655 6.1 警告
Network
シスコシステムズ - Cisco Unified Communications Domain Manager の Web ベースの GUI におけるリダイレクトされる脆弱性 CWE-601
オープンリダイレクト
CVE-2017-6670 2017-07-10 16:57 2017-06-7 Show GitHub Exploit DB Packet Storm
191656 4.9 警告
Network
シスコシステムズ - Cisco Unified Communications Domain Manager の Web ベースの GUI におけるシステムの機密性に影響を及ぼされる脆弱性 CWE-89
SQLインジェクション
CVE-2017-6668 2017-07-10 16:57 2017-06-7 Show GitHub Exploit DB Packet Storm
191657 9.8 緊急
Network
シスコシステムズ - Cisco Context Service software development kit の 動的 JAR ファイルのアップデート処理における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2017-6667 2017-07-10 16:57 2017-06-7 Show GitHub Exploit DB Packet Storm
191658 9.8 緊急
Network
DesignerFreeSolutions - nuevoMailer の rdr.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-9730 2017-07-10 16:56 2017-06-16 Show GitHub Exploit DB Packet Storm
191659 7 重要
Local
Google - Android の MediaTek コマンドキュードライバにおける認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-0636 2017-07-10 16:56 2017-06-5 Show GitHub Exploit DB Packet Storm
191660 5.9 警告
Network
North Adams State Bank of Ursa Inc - iOS 用 North Adams State Bank nasb-mobile-banking アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9573 2017-07-10 16:54 2017-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
721 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name o… Update NVD-CWE-noinfo
CVE-2026-43118 2026-05-9 02:30 2026-05-6 Show GitHub Exploit DB Packet Storm
722 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm-verity: correctly handle dm_bufio_client_create() failure If either of the calls to dm_bufio_client_create() in verity_fec_ctr… Update NVD-CWE-noinfo
CVE-2026-43132 2026-05-9 02:26 2026-05-6 Show GitHub Exploit DB Packet Storm
723 7.9 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload o… Update NVD-CWE-noinfo
CVE-2026-43133 2026-05-9 02:25 2026-05-6 Show GitHub Exploit DB Packet Storm
724 4.8 MEDIUM
Network
linuxcontainers incus Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database… Update CWE-295
Improper Certificate Validation 
CVE-2026-40243 2026-05-9 02:23 2026-05-7 Show GitHub Exploit DB Packet Storm
725 8.2 HIGH
Network
quarkus quarkus Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec… Update CWE-863
 Incorrect Authorization
CVE-2026-39852 2026-05-9 02:18 2026-05-6 Show GitHub Exploit DB Packet Storm
726 - - - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.P… New CWE-79
Cross-site Scripting
CVE-2026-42794 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
727 9.8 CRITICAL
Network
- - Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRE… New CWE-1392
 Use of Default Credentials
CVE-2026-42072 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
728 6.1 MEDIUM
Network
- - MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker t… New CWE-80
Basic XSS
CVE-2026-42030 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
729 - - - pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, t… New CWE-89
SQL Injection
CVE-2026-41889 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
730 4.9 MEDIUM
Network
- - Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but th… New CWE-22
CWE-918
Path Traversal
Server-Side Request Forgery (SSRF) 
CVE-2026-41887 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm