Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 12:06 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192921 8.8 重要
Network
Atlassian - Atlassian Hipchat Server における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-8080 2017-06-13 11:23 2017-04-24 Show GitHub Exploit DB Packet Storm
192922 9.8 緊急
Network
Accellion - Accellion FTA デバイスの seos/courier/communication_p2p.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-8796 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192923 6.1 警告
Network
Accellion - Accellion FTA デバイスの home/seos/courier/smtpg_add.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-8795 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192924 10 緊急
Network
Accellion - Accellion FTA デバイスの courier/web/1000@/wmProgressval.html におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2017-8794 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192925 8.8 重要
Network
Accellion - Accellion FTA デバイスにおける認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-8793 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192926 6.1 警告
Network
Accellion - Accellion FTA デバイスの home/seos/courier/user_add.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-8792 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192927 6.1 警告
Network
Accellion - Accellion FTA デバイスにおける CRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2017-8791 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192928 9.8 緊急
Network
Accellion - Accellion FTA デバイスの home/seos/courier/ldaptest.html における LDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2017-8790 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192929 9.8 緊急
Network
Accellion - Accellion FTA デバイスにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-8789 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
192930 6.1 警告
Network
Accellion - Accellion FTA デバイスの settings_global_text_edit.php における CRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2017-8788 2017-06-12 18:24 2017-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1641 8.1 HIGH
Network
- - Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41105 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1642 10.0 CRITICAL
Network
- - Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. CWE-200
Information Exposure
CVE-2026-42826 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1643 6.3 MEDIUM
Network
- - A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-8114 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1644 5.3 MEDIUM
Network
- - A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the… CWE-22
Path Traversal
CVE-2026-8115 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1645 6.3 MEDIUM
Network
- - A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxtController.ts. This manipulation of the argument m… CWE-22
Path Traversal
CVE-2026-8116 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1646 6.3 MEDIUM
Network
- - A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users API Endpoint. Such manipulation leads to improper… CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-8127 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1647 7.3 HIGH
Network
- - A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Fileli… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-8133 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
1648 3.3 LOW
Local
- - A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. … CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-8124 2026-05-9 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
1649 8.8 HIGH
Network
- - The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and … CWE-502
 Deserialization of Untrusted Data
CVE-2026-5127 2026-05-9 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
1650 7.2 HIGH
Network
- - The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST par… CWE-79
Cross-site Scripting
CVE-2026-7330 2026-05-9 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm