Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194701 7.8 重要
Local
Delta Electronics - 複数の Delta Electronics 製品におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-5805 2017-04-4 15:56 2016-12-13 Show GitHub Exploit DB Packet Storm
194702 7.8 重要
Local
Delta Electronics - 複数の Delta Electronics 製品における悪意のあるファイルを読み込まれる脆弱性 CWE-787
境界外書き込み
CVE-2016-5802 2017-04-4 15:56 2016-12-13 Show GitHub Exploit DB Packet Storm
194703 6.5 警告
Adjacent
ASUSTeK Computer Inc. - ASUS RT-N56U Wireless Router のファームウェアにおける脆弱性 CWE-noinfo
情報不足
CVE-2017-5632 2017-04-4 15:54 2017-01-29 Show GitHub Exploit DB Packet Storm
194704 7.2 重要
Network
ソフォス - Sophos Web Appliance Remote / Secure Web Gateway サーバの Web 管理インターフェースにおけるリモートコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2016-9554 2017-04-4 15:38 2016-11-22 Show GitHub Exploit DB Packet Storm
194705 7.8 重要
Local
CA Technologies - 複数の CA 製品で使用される CA Common Services の casrvc プログラムにおける任意のファイルを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2016-9795 2017-04-4 15:30 2016-12-2 Show GitHub Exploit DB Packet Storm
194706 8.8 重要
Network
マカフィー - McAfee Virus Scan Enterprise for Linux に複数の脆弱性 CWE-113
CWE-200
CWE-290
CWE-302
CWE-347
CWE-352
CWE-75
CWE-79
CWE-89
CWE-94
CVE-2016-8016
CVE-2016-8017
CVE-2016-8018
CVE-2016-8019
CVE-2016-8020
CVE-2016-8021
CVE-2016-8022
CVE-2016-8023
CVE-2016-8024
CVE-2016-8025
2017-04-4 15:18 2016-12-12 Show GitHub Exploit DB Packet Storm
194707 8.6 重要
Network
Locus Energy - 複数の Locus Energy LGate 製品における脆弱性 CWE-20
不適切な入力確認
CVE-2016-5782 2017-04-4 15:10 2016-12-6 Show GitHub Exploit DB Packet Storm
194708 7.2 重要
Network
XOOPS - XOOPS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-7290 2017-04-4 11:31 2017-03-30 Show GitHub Exploit DB Packet Storm
194709 7.2 重要
Network
DELL EMC (旧 EMC Corporation) - EMC Isilon OneFS における権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-9871 2017-04-3 18:27 2016-12-6 Show GitHub Exploit DB Packet Storm
194710 5.3 警告
Network
DELL EMC (旧 EMC Corporation) - EMC RSA BSAFE Crypto-J の PKCS#12 ファイルにおけるタイミング攻撃を実行される脆弱性 CWE-200
情報漏えい
CVE-2016-8217 2017-04-3 18:27 2016-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
821 7.5 HIGH
Network
- - @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct bu… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-7768 2026-05-5 05:16 2026-05-5 Show GitHub Exploit DB Packet Storm
822 7.5 HIGH
Network
- - fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and par… New CWE-22
Path Traversal
CVE-2026-6321 2026-05-5 05:16 2026-05-5 Show GitHub Exploit DB Packet Storm
823 7.8 HIGH
Local
wireshark wireshark RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Update CWE-122
CWE-787
Heap-based Buffer Overflow
 Out-of-bounds Write
CVE-2026-5405 2026-05-5 05:16 2026-05-1 Show GitHub Exploit DB Packet Storm
824 - - - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-6074. Reason: This record is a reservation duplicate of CVE-2026-6074. Notes: All CVE users should reference CVE-2026-6074 instead of… New - CVE-2026-34882 2026-05-5 05:16 2026-05-5 Show GitHub Exploit DB Packet Storm
825 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a… New CWE-400
CWE-789
 Uncontrolled Resource Consumption
 Memory Allocation with Excessive Size Value
CVE-2026-42154 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
826 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/a… New CWE-200
CWE-312
Information Exposure
 Cleartext Storage of Sensitive Information
CVE-2026-42151 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
827 - - - Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in … New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41686 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
828 5.5 MEDIUM
Local
absolute secure_access CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-40951 2026-05-5 03:54 2026-05-1 Show GitHub Exploit DB Packet Storm
829 9.8 CRITICAL
Network
tenda w308r_firmware Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25316 2026-05-5 03:42 2026-04-30 Show GitHub Exploit DB Packet Storm
830 9.8 CRITICAL
Network
tenda fh303_firmware
a300_firmware
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25318 2026-05-5 03:40 2026-04-30 Show GitHub Exploit DB Packet Storm