Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192711 9.8 緊急
Network
ICU project
Google
- Google Chrome で使用される C/C++ 用 ICU の Regular Expressions パッケージにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2014-9654 2017-06-1 17:24 2014-11-19 Show GitHub Exploit DB Packet Storm
192712 6.1 警告
Network
株式会社内田洋行 - ASSETBASE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-2134 2017-06-1 17:14 2017-04-11 Show GitHub Exploit DB Packet Storm
192713 7.8 重要
Local
株式会社セキュアブレイン - PhishWall クライアント Internet Explorer版のインストーラにおける任意の DLL 読み込みに関する脆弱性 CWE-Other
その他
CVE-2017-2130 2017-06-1 17:11 2017-03-22 Show GitHub Exploit DB Packet Storm
192714 9.8 緊急
Network
PoDoFo project - PoDoFo の base/PdfParser.cpp の PdfParser::ReadObjects 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-8378 2017-06-1 17:02 2017-05-4 Show GitHub Exploit DB Packet Storm
192715 5.3 警告
Network
ジュニパーネットワークス - Juniper Networks Junos OS における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-2340 2017-06-1 17:02 2017-04-12 Show GitHub Exploit DB Packet Storm
192716 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle One-to-One Fulfillment における Audience workbench に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3434 2017-06-1 17:00 2017-04-18 Show GitHub Exploit DB Packet Storm
192717 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における User Interface に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3356 2017-06-1 17:00 2017-04-18 Show GitHub Exploit DB Packet Storm
192718 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における User Interface に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3355 2017-06-1 17:00 2017-04-18 Show GitHub Exploit DB Packet Storm
192719 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における User Interface に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3347 2017-06-1 17:00 2017-04-18 Show GitHub Exploit DB Packet Storm
192720 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における User Interface に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3345 2017-06-1 17:00 2017-04-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1381 9.4 CRITICAL
Network
- - Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored pas… CWE-287
Improper Authentication
CVE-2026-41571 2026-05-7 06:25 2026-05-5 Show GitHub Exploit DB Packet Storm
1382 - - - FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser control… CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-32699 2026-05-7 06:25 2026-05-6 Show GitHub Exploit DB Packet Storm
1383 - - - Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management … CWE-352
 Origin Validation Error
CVE-2026-40174 2026-05-7 06:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1384 - - - Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requests. An attacker ca… CWE-352
 Origin Validation Error
CVE-2026-40309 2026-05-7 06:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1385 - - - Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate anti-CSRF tokens for content restoration requests… CWE-352
 Origin Validation Error
CVE-2026-40325 2026-05-7 06:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1386 - - - Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not properly validate anti-CSRF tokens for site bundle cre… CWE-352
 Origin Validation Error
CVE-2026-40326 2026-05-7 06:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1387 - - - Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths beginning with double slashes (//) as internal pa… CWE-601
Open Redirect
CVE-2026-40332 2026-05-7 06:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1388 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fuse: abort on fatal signal during sync init When sync init is used and the server exits for some reason (error, crash) while pro… NVD-CWE-noinfo
CVE-2026-31713 2026-05-7 06:13 2026-05-1 Show GitHub Exploit DB Packet Storm
1389 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid memory leak in f2fs_rename() syzbot reported a f2fs bug as below: BUG: memory leak unreferenced object 0xffff… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-31714 2026-05-7 06:12 2026-05-1 Show GitHub Exploit DB Packet Storm
1390 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file record check check_file_record() validates rec->total against the record size… CWE-787
 Out-of-bounds Write
CVE-2026-31716 2026-05-7 06:10 2026-05-1 Show GitHub Exploit DB Packet Storm