Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194861 6.5 警告
Local
Fabrice Bellard - QEMU の hw/9pfs/9p.c の v9fs_device_unrealize_common 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-400
リソースの枯渇
CVE-2016-9913 2017-01-12 15:26 2016-11-16 Show GitHub Exploit DB Packet Storm
194862 6.5 警告
Local
Fabrice Bellard - Virtio GPU デバイスエミュレータサポートでビルドされた QEMU におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-9846 2017-01-12 15:26 2016-11-1 Show GitHub Exploit DB Packet Storm
194863 6.5 警告
Local
Fabrice Bellard - Virtio GPU デバイスエミュレータサポートでビルドされた QEMU における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2016-9845 2017-01-12 15:26 2016-11-1 Show GitHub Exploit DB Packet Storm
194864 5.5 警告
Local
Fabrice Bellard - ColdFire Fast Ethernet Controller エミュレータサポートでビルドされた QEMU におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-9776 2017-01-12 15:26 2016-11-29 Show GitHub Exploit DB Packet Storm
194865 7.8 重要
Local
マイクロソフト - Microsoft Word 2016 および SharePoint Enterprise Server 2016 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2017-0003 2017-01-12 11:28 2017-01-10 Show GitHub Exploit DB Packet Storm
194866 8.8 重要
Network
マイクロソフト - Microsoft Edge における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-0002 2017-01-12 11:28 2017-01-10 Show GitHub Exploit DB Packet Storm
194867 9.8 緊急
Network
クイックヒール・テクノロジーズ・ジャパン株式会社 - Mac OS X 上で稼動する Quick Heal の複数の製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-5005 2017-01-11 17:59 2017-01-2 Show GitHub Exploit DB Packet Storm
194868 6.5 警告
Network
ネットギア - 複数の NETGEAR デバイス製品のファームウェアの scgi-bin/platform.cgi におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-10106 2017-01-11 17:54 2016-11-28 Show GitHub Exploit DB Packet Storm
194869 9.8 緊急
Network
Piwigo - Piwigo の admin/plugin.php における情報漏えいの脆弱性 CWE-200
CWE-284
CVE-2016-10105 2017-01-11 17:37 2016-12-19 Show GitHub Exploit DB Packet Storm
194870 7.2 重要
Network
Piwigo - Piwigo の admin/languages.php におけるファイルインクルージョン攻撃を実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-10085 2017-01-11 17:37 2016-12-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
341 6.1 MEDIUM
Network
- - zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/… CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-40302 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
342 4.7 MEDIUM
Network
- - DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() refe… CWE-79
Cross-site Scripting
CVE-2026-40301 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
343 - - - next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and … CWE-601
Open Redirect
CVE-2026-40299 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
344 6.5 MEDIUM
Network
- - OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabl… CWE-200
Information Exposure
CVE-2026-40293 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
345 7.5 HIGH
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) functi… CWE-79
Cross-site Scripting
CVE-2026-40286 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
346 6.8 MEDIUM
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the … CWE-79
Cross-site Scripting
CVE-2026-40284 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
347 - - - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the… CWE-79
Cross-site Scripting
CVE-2026-40282 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
348 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
349 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
350 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm