Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193631 7 重要
Local
IBM - IBM Spectrum Protect Operations Center における以前にログインしたユーザを継承される脆弱性 CWE-384
セッションの固定化
CVE-2016-6043 2017-02-22 14:30 2016-12-20 Show GitHub Exploit DB Packet Storm
193632 7.3 重要
Local
IBM - IBM Security AppScan Enterprise エディションにおけるシステム上で任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-6042 2017-02-22 11:56 2016-12-6 Show GitHub Exploit DB Packet Storm
193633 6.1 警告
Network
IBM - IBM Sterling B2B Integrator Standard Edition におけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2016-6020 2017-02-22 11:55 2016-12-21 Show GitHub Exploit DB Packet Storm
193634 5.4 警告
Network
IBM - IBM TRIRIGA Application Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5980 2017-02-22 11:54 2016-10-17 Show GitHub Exploit DB Packet Storm
193635 5.5 警告
Local
IBM - IBM BigFix Inventory におけるユーザの認証情報を読まれる脆弱性 CWE-255
証明書・パスワード管理
CVE-2016-8967 2017-02-22 11:35 2016-10-25 Show GitHub Exploit DB Packet Storm
193636 5.4 警告
Network
IBM - IBM WebSphere Application Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-8934 2017-02-22 11:30 2016-12-5 Show GitHub Exploit DB Packet Storm
193637 5.9 警告
Network
IBM - IBM Integration Bus 有効な資格情報を提供せずに認証される脆弱性 CWE-255
証明書・パスワード管理
CVE-2016-8918 2017-02-22 11:28 2016-12-2 Show GitHub Exploit DB Packet Storm
193638 5.4 警告
Network
IBM - IBM Maximo Asset Management におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6072 2017-02-22 11:27 2016-10-31 Show GitHub Exploit DB Packet Storm
193639 6.5 警告
Network
IBM - IBM Kenexa LCMS Premier on Cloud における認証情報を読まれる脆弱性 CWE-255
証明書・パスワード管理
CVE-2016-5950 2017-02-22 11:25 2016-06-29 Show GitHub Exploit DB Packet Storm
193640 4.3 警告
Network
IBM - IBM Kenexa LCMS Premier on Cloud における重要なユーザデータを取得される脆弱性 CWE-254
セキュリティ機能
CVE-2016-5949 2017-02-22 11:25 2016-10-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 22, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
301 8.8 HIGH
Local
- - Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b… CWE-78
CWE-116
OS Command 
 Improper Encoding or Escaping of Output
CVE-2026-35582 2026-04-18 11:16 2026-04-18 Show GitHub Exploit DB Packet Storm
302 6.1 MEDIUM
Network
- - The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and… CWE-79
Cross-site Scripting
CVE-2026-1838 2026-04-18 11:16 2026-04-18 Show GitHub Exploit DB Packet Storm
303 6.4 MEDIUM
Network
- - The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization a… CWE-79
Cross-site Scripting
CVE-2026-1559 2026-04-18 11:16 2026-04-18 Show GitHub Exploit DB Packet Storm
304 9.0 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address … CWE-269
 Improper Privilege Management
CVE-2026-40572 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
305 8.8 HIGH
Network
- - Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use t… CWE-863
 Incorrect Authorization
CVE-2026-40350 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
306 7.5 HIGH
Network
- - SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se… CWE-36
CWE-73
 Absolute Path Traversal
 External Control of File Name or Path
CVE-2026-35465 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
307 8.8 HIGH
Network
- - Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=… CWE-862
 Missing Authorization
CVE-2026-40349 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
308 5.3 MEDIUM
Network
- - Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or… CWE-400
CWE-834
 Uncontrolled Resource Consumption
 Excessive Iteration
CVE-2026-40347 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
309 - - - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request ac… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40346 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
310 3.5 LOW
Physics
- - libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input f… CWE-126
 Buffer Over-read
CVE-2026-40341 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm