Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194471 9.1 緊急
Network
オラクル - Oracle E-Business Suite の Oracle Scripting における Scripting Administration に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3549 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194472 5.4 警告
Network
オラクル - Oracle E-Business Suite の Oracle Applications Framework における Popup windows (lists of values, datepicker, etc.) に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3528 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194473 5.4 警告
Network
オラクル - Oracle E-Business Suite の Oracle User Management における User Name/Password Management に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3515 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194474 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle One-to-One Fulfillment における Audience workbench に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3432 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194475 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Advanced Outbound Telephony における Interaction History に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3393 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194476 7.1 重要
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における User Interface に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3337 2017-05-29 18:15 2017-04-18 Show GitHub Exploit DB Packet Storm
194477 8.4 重要
Local
オラクル - Oracle Virtualization の Oracle VM VirtualBox における Shared Folder に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3587 2017-05-29 17:23 2017-04-18 Show GitHub Exploit DB Packet Storm
194478 8.8 重要
Local
オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3576 2017-05-29 17:23 2017-04-18 Show GitHub Exploit DB Packet Storm
194479 7.9 重要
Local
オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3575 2017-05-29 17:23 2017-04-18 Show GitHub Exploit DB Packet Storm
194480 8.8 重要
Local
オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3563 2017-05-29 17:23 2017-04-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1651 8.0 HIGH
Network
- - Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-41431 2026-05-14 00:37 2026-05-12 Show GitHub Exploit DB Packet Storm
1652 2.4 LOW
Network
- - Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same r… CWE-20
 Improper Input Validation 
CVE-2026-44658 2026-05-14 00:37 2026-05-12 Show GitHub Exploit DB Packet Storm
1653 4.7 MEDIUM
Network
- - Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the a… CWE-451
 User Interface (UI) Misrepresentation of Critical Information
CVE-2026-44659 2026-05-14 00:37 2026-05-12 Show GitHub Exploit DB Packet Storm
1654 - - - An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections … CWE-502
CWE-918
 Deserialization of Untrusted Data
Server-Side Request Forgery (SSRF) 
CVE-2026-3048 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1655 - - - An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via … CWE-79
Cross-site Scripting
CVE-2026-7308 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1656 - - - Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploi… CWE-79
Cross-site Scripting
CVE-2026-3319 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1657 - - - Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitat… CWE-79
Cross-site Scripting
CVE-2026-3320 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1658 - - - Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-8072 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1659 7.7 HIGH
Network
- - In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-33356 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm
1660 7.5 HIGH
Network
- - In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearic… CWE-862
 Missing Authorization
CVE-2026-33357 2026-05-14 00:36 2026-05-12 Show GitHub Exploit DB Packet Storm