Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194361 7.5 重要
Network
Tiki Software Community Association - Tiki Wiki CMS におけるシステム上で任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-10143 2017-01-31 14:12 2016-11-17 Show GitHub Exploit DB Packet Storm
194362 5.9 警告
Network
JCraft, Inc. - Windows 上で稼動する JCraft JSch におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-5725 2017-01-31 14:01 2016-08-30 Show GitHub Exploit DB Packet Storm
194363 8.8 重要
Local
Firejail project - Firejail におけるサンドボックス外で任意のコマンドを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-9016 2017-01-31 13:54 2016-10-25 Show GitHub Exploit DB Packet Storm
194364 9.8 緊急
Network
Sociomantic Labs - sociomantic-tsunami git-hub における任意のコードを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-7794 2017-01-31 13:50 2016-09-7 Show GitHub Exploit DB Packet Storm
194365 8.8 重要
Network
Sociomantic Labs - sociomantic-tsunami git-hub における任意のコードを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-7793 2017-01-31 13:50 2016-09-7 Show GitHub Exploit DB Packet Storm
194366 4 警告
Local
Info-ZIP - Info-Zip UnZip の list.c の list_files 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-9913 2017-01-31 13:36 2014-11-3 Show GitHub Exploit DB Packet Storm
194367 6.1 警告
Network
BlackBerry - BlackBerry の WatchDox サーバコンポーネントの Appliance-X および vApp における反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-3890 2017-01-31 12:23 2017-01-10 Show GitHub Exploit DB Packet Storm
194368 9.8 緊急
Network
Intelliants - Subrion CMS の includes/classes/ia.core.users.php における PHP オブジェクトインジェクション攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2017-5543 2017-01-31 11:33 2017-01-17 Show GitHub Exploit DB Packet Storm
194369 6.1 警告
Network
Symphony CMS - Symphony CMS の template/usererror.missing_extension.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-5542 2017-01-31 11:31 2017-01-18 Show GitHub Exploit DB Packet Storm
194370 5.3 警告
Network
Symphony CMS - Symphony CMS の template/usererror.missing_extension.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2017-5541 2017-01-31 11:31 2017-01-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
991 5.9 MEDIUM
Network
- - A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. New CWE-353
 Missing Support for Integrity Check
CVE-2026-33261 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
992 5.9 MEDIUM
Network
- - An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default. New CWE-476
 NULL Pointer Dereference
CVE-2026-33262 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
993 4.4 MEDIUM
Network
- - An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. New CWE-476
 NULL Pointer Dereference
CVE-2026-33600 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
994 4.4 MEDIUM
Network
- - If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to … New CWE-476
 NULL Pointer Dereference
CVE-2026-33601 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
995 5.4 MEDIUM
Network
- - A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be… New CWE-613
 Insufficient Session Expiration
CVE-2026-6848 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
996 7.1 HIGH
Local
- - A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create… New CWE-22
Path Traversal
CVE-2026-6855 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
997 7.5 HIGH
Network
- - A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by … New CWE-502
 Deserialization of Untrusted Data
CVE-2026-6857 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
998 - - - Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This … New CWE-276
Incorrect Default Permissions 
CVE-2026-0539 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
999 6.5 MEDIUM
Network
- - Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request. New CWE-20
CWE-284
 Improper Input Validation 
Improper Access Control
CVE-2026-31192 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm
1000 5.3 MEDIUM
Network
- - An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default. New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-33254 2026-04-23 06:23 2026-04-22 Show GitHub Exploit DB Packet Storm