Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 12:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192021 5.4 警告
Network
Telaxus LLC - Telaxus EPESI の Agenda コンポーネントにおける格納型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-9331 2017-06-30 13:54 2017-05-29 Show GitHub Exploit DB Packet Storm
192022 6.5 警告
Network
Allen Disk project - Allen Disk の remotedownload.php におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2017-9307 2017-06-30 13:54 2017-05-9 Show GitHub Exploit DB Packet Storm
192023 6.1 警告
Network
FlipBuilder - FlipBuilder Flip PDF におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-7384 2017-06-30 13:54 2017-05-31 Show GitHub Exploit DB Packet Storm
192024 6.7 警告
Local
インテル - Intel Solid State Drive Toolbox における権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-5688 2017-06-30 13:54 2017-05-30 Show GitHub Exploit DB Packet Storm
192025 5.5 警告
Local
VMware - VMware Horizon DaaS における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-4897 2017-06-30 13:54 2017-03-2 Show GitHub Exploit DB Packet Storm
192026 9.8 緊急
Network
Ceragon Ltd. - Ceragon FibeAir IP-10 における SSH アクセス権を取得される脆弱性 CWE-320
鍵管理のエラー
CVE-2015-0936 2017-06-30 13:54 2015-03-26 Show GitHub Exploit DB Packet Storm
192027 5.3 警告
Network
ジュニパーネットワークス - Juniper Networks Junos Space のホストベースのファイアウォールにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-2310 2017-06-30 13:52 2017-01-11 Show GitHub Exploit DB Packet Storm
192028 5.9 警告
Network
ジュニパーネットワークス - Juniper Networks Junos Space における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2017-2309 2017-06-30 13:52 2017-01-11 Show GitHub Exploit DB Packet Storm
192029 7.5 重要
Network
ジュニパーネットワークス - Juniper Networks SRX シリーズサービスゲートウェイのシャーシクラスタ上で稼動する Junos OS におけるデータ処理に関する脆弱性 CWE-19
データ処理
CVE-2017-2300 2017-06-30 13:52 2017-01-11 Show GitHub Exploit DB Packet Storm
192030 7.8 重要
Local
マイクロソフト - Windows XP および Windows Server 2003 の Windows OLE におけるコードを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-8487 2017-06-30 12:06 2017-06-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1111 8.6 HIGH
Network
- - Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to… CWE-121
Stack-based Buffer Overflow
CVE-2026-42469 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1112 6.1 MEDIUM
Network
- - Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-suppli… CWE-79
Cross-site Scripting
CVE-2025-69606 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1113 6.5 MEDIUM
Network
- - A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request. CWE-77
Command Injection
CVE-2026-26461 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1114 7.5 HIGH
Network
- - An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) … CWE-787
 Out-of-bounds Write
CVE-2026-37457 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1115 6.5 MEDIUM
Network
- - goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the C… CWE-352
 Origin Validation Error
CVE-2026-42091 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1116 - - - Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/fi… CWE-79
Cross-site Scripting
CVE-2026-42138 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1117 - - - Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41686 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1118 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/a… CWE-200
CWE-312
Information Exposure
 Cleartext Storage of Sensitive Information
CVE-2026-42151 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1119 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a… CWE-400
CWE-789
 Uncontrolled Resource Consumption
 Memory Allocation with Excessive Size Value
CVE-2026-42154 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1120 3.7 LOW
Network
- - Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number. CWE-193
 Off-by-one Error
CVE-2026-43964 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm