Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192891 6.1 警告
Network
NETIKUS.NET ltd - Netikus EventSentry におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5077 2017-05-12 18:00 2016-09-7 Show GitHub Exploit DB Packet Storm
192892 6.1 警告
Network
Paessler AG - Paessler PRTG におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5078 2017-05-12 17:54 2016-09-7 Show GitHub Exploit DB Packet Storm
192893 6.1 警告
Network
SmartBear Software - Swagger-UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5682 2017-05-12 17:52 2016-09-2 Show GitHub Exploit DB Packet Storm
192894 5.4 警告
Network
Opmantek - Opmantek NMIS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5642 2017-05-12 17:50 2016-09-7 Show GitHub Exploit DB Packet Storm
192895 6.1 警告
Network
Spiceworks Inc. - Spiceworks Desktop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-6021 2017-05-12 17:39 2015-12-16 Show GitHub Exploit DB Packet Storm
192896 7.5 重要
Network
ImageMagick - ImageMagick における無限ループに関する脆弱性 CWE-835
無限ループ
CVE-2017-7619 2017-05-12 17:32 2017-03-2 Show GitHub Exploit DB Packet Storm
192897 7.5 重要
Network
Opmantek - Opmantek NMIS におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2016-6534 2017-05-12 17:31 2016-09-7 Show GitHub Exploit DB Packet Storm
192898 7.5 重要
Network
NetApp - NetApp Clustered Data ONTAP におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2017-5988 2017-05-12 17:21 2017-03-31 Show GitHub Exploit DB Packet Storm
192899 7.5 重要
Network
フィリップス - Philips In.Sight B120/37 における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-2884 2017-05-12 17:19 2015-09-2 Show GitHub Exploit DB Packet Storm
192900 5.4 警告
Network
フィリップス - Philips In.Sight B120/37 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2883 2017-05-12 17:19 2015-09-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
861 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security… CWE-307
CWE-362
CWE-367
mproper Restriction of Excessive Authentication Attempts
Race Condition
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-26206 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
862 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() i… CWE-121
CWE-400
Stack-based Buffer Overflow
 Uncontrolled Resource Consumption
CVE-2026-28221 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
863 9.0 CRITICAL
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchroniz… CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-30893 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
864 9.8 CRITICAL
Network
- - Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se… CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25317 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
865 7.4 HIGH
Network
- - Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects … CWE-125
Out-of-bounds Read
CVE-2026-42799 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
866 7.4 HIGH
Network
- - NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/s… CWE-476
 NULL Pointer Dereference
CVE-2026-42800 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
867 6.5 MEDIUM
Network
- - Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.… CWE-200
CWE-359
Information Exposure
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-7382 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
868 8.1 HIGH
Network
- - Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-7399 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
869 8.1 HIGH
Network
- - Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. CWE-799
 Improper Control of Interaction Frequency
CVE-2026-7402 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
870 7.5 HIGH
Network
frappe press Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like expl… CWE-352
 Origin Validation Error
CVE-2026-41317 2026-04-30 23:53 2026-04-24 Show GitHub Exploit DB Packet Storm