Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193931 7 重要
Local
Google - Android の TrustZone における競合状態に関する脆弱性 CWE-362
競合状態
CVE-2016-10297 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193932 7.8 重要
Local
Google - Android の TrustZone における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2015-9007 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193933 7.8 重要
Local
Google - Android の TrustZone における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2015-9005 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193934 5.5 警告
Local
Google - Android の TrustZone における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2014-9951 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193935 7.8 重要
Local
Google - Android の TrustZone における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2014-9949 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193936 7.8 重要
Local
Google - Android の TrustZone における配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2014-9948 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193937 5.5 警告
Local
Google - Android の TrustZone における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2014-9947 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193938 7.8 重要
Local
Google - Android の TrustZone における認可に関する脆弱性 CWE-285
不適切な認可
CVE-2014-9945 2017-06-26 17:35 2017-05-1 Show GitHub Exploit DB Packet Storm
193939 8.8 重要
Network
Mercurial - Mercurial の "hg serve --stdio" における Python デバッガを起動される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-9462 2017-06-26 16:24 2017-04-18 Show GitHub Exploit DB Packet Storm
193940 7.8 重要
Local
Lenovo - Lenovo Solution Center のバックエンドサービスプロセスにおけるシステム権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1876 2017-06-26 16:06 2016-04-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1971 7.5 HIGH
Network
protobufjs_project protobufjs protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected bo… CWE-674
 Uncontrolled Recursion
CVE-2026-44289 2026-05-14 05:50 2026-05-14 Show GitHub Exploit DB Packet Storm
1972 7.5 HIGH
Network
protobufjs_project protobufjs protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.… CWE-674
 Uncontrolled Recursion
CVE-2026-45740 2026-05-14 05:50 2026-05-14 Show GitHub Exploit DB Packet Storm
1973 8.8 HIGH
Network
microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-502
 Deserialization of Untrusted Data
CVE-2026-40357 2026-05-14 05:48 2026-05-13 Show GitHub Exploit DB Packet Storm
1974 9.6 CRITICAL
Network
ivanti xtraction External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to … CWE-73
 External Control of File Name or Path
CVE-2026-8043 2026-05-14 05:34 2026-05-13 Show GitHub Exploit DB Packet Storm
1975 5.0 MEDIUM
Local
- - csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories. CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-41051 2026-05-14 05:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1976 7.8 HIGH
Local
adobe substance_3d_designer Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … CWE-787
 Out-of-bounds Write
CVE-2026-34684 2026-05-14 05:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1977 7.8 HIGH
Local
adobe substance_3d_designer Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … CWE-787
 Out-of-bounds Write
CVE-2026-34683 2026-05-14 05:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1978 5.9 MEDIUM
Network
vercel next.js Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fe… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44577 2026-05-14 05:00 2026-05-14 Show GitHub Exploit DB Packet Storm
1979 5.5 MEDIUM
Local
pengutronix barebox barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directo… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-34962 2026-05-14 04:58 2026-05-12 Show GitHub Exploit DB Packet Storm
1980 7.7 HIGH
Local
pengutronix barebox barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.… CWE-125
Out-of-bounds Read
CVE-2026-34961 2026-05-14 04:57 2026-05-12 Show GitHub Exploit DB Packet Storm