Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191981 5.9 警告
Network
MEA Financial Enterprises, L.L.C. - iOS 用 Community Bank's CB2GO アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9564 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191982 5.9 警告
Network
MEA Financial Enterprises, L.L.C. - iOS 用 FCCB アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9563 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191983 5.9 警告
Network
MEA Financial Enterprises, L.L.C. - iOS 用 Freedom 1st Credit Union Mobile Banking アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9562 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191984 5.9 警告
Network
Cayuga Lake National Bank Inc - iOS 用 Cayuga Lake National Bank アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9560 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191985 5.9 警告
Network
MEA Financial Enterprises, L.L.C. - iOS 用 Vision Bank アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9559 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191986 5.9 警告
Network
Wawa Employees Credit Union - iOS 用 Wawa Employees Credit Union Mobile アプリケーションにおけるサーバになりすまされる脆弱性 CWE-295
不正な証明書検証
CVE-2017-9558 2017-07-12 14:27 2017-06-12 Show GitHub Exploit DB Packet Storm
191987 6 警告
Local
シスコシステムズ - Cisco Network Convergence System 5500 シリーズルータ用 Cisco IOS XR ソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-6666 2017-07-12 13:48 2017-06-7 Show GitHub Exploit DB Packet Storm
191988 9.8 緊急
Network
Red5 - Red5 Media Server の AMF unmarshaller における任意のコードを実行される脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2017-5878 2017-07-11 18:07 2017-05-22 Show GitHub Exploit DB Packet Storm
191989 5.4 警告
Network
SAP - SAP SuccessFactors における格納型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-9613 2017-07-11 17:52 2017-06-15 Show GitHub Exploit DB Packet Storm
191990 6.1 警告
Network
Elasticsearch - Kibana におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-10366 2017-07-11 17:46 2016-10-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1441 5.3 MEDIUM
Network
- - A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/… New CWE-400
CWE-404
 Uncontrolled Resource Consumption
 Improper Resource Shutdown or Release
CVE-2026-8319 2026-05-13 01:38 2026-05-12 Show GitHub Exploit DB Packet Storm
1442 4.7 MEDIUM
Network
- - A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of … New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-8320 2026-05-13 01:38 2026-05-12 Show GitHub Exploit DB Packet Storm
1443 - - - CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ra… New CWE-1188
 Insecure Default Initialization of Resource
CVE-2026-6866 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1444 4.4 MEDIUM
Local
- - An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh… New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-7431 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1445 7.8 HIGH
Local
- - A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM New CWE-362
Race Condition
CVE-2026-7432 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1446 7.2 HIGH
Network
- - OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. New CWE-78
OS Command 
CVE-2026-8051 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1447 6.5 MEDIUM
Network
- - An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. New CWE-749
 Exposed Dangerous Method or Function
CVE-2026-8109 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1448 7.8 HIGH
Local
- - Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-8110 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1449 8.8 HIGH
Network
- - SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. New CWE-89
SQL Injection
CVE-2026-8111 2026-05-13 01:38 2026-05-13 Show GitHub Exploit DB Packet Storm
1450 8.8 HIGH
Network
pi-hole ftldns Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac… Update CWE-93
CRLF Injection
CVE-2026-39849 2026-05-13 01:27 2026-05-6 Show GitHub Exploit DB Packet Storm