Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195171 7.5 重要
Network
CA Technologies - CA Unified Infrastructure Management および Unified Infrastructure Management Snap の diag.jsp ファイルにおける任意のファイルを読まれる脆弱性 CWE-22
パス・トラバーサル
CVE-2016-9164 2017-03-30 16:00 2016-11-9 Show GitHub Exploit DB Packet Storm
195172 5.9 警告
Network
OpenBSD - OpenSSH の sshd におけるユーザを列挙される脆弱性 CWE-200
情報漏えい
CVE-2016-6210 2017-03-30 16:00 2016-07-14 Show GitHub Exploit DB Packet Storm
195173 7.8 重要
Local
freedesktop.org - pkexec における親セッションにエスケープされる脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2016-2568 2017-03-30 15:47 2016-01-21 Show GitHub Exploit DB Packet Storm
195174 7.5 重要
Network
Webkit - Webkit の regex コードにおけるサービス運用妨害 (DoS) の脆弱性 CWE-400
リソースの枯渇
CVE-2016-9643 2017-03-30 15:44 2016-11-26 Show GitHub Exploit DB Packet Storm
195175 6.1 警告
Network
MantisBT Group - MantisBT の view_filters_page.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6799 2017-03-30 15:39 2017-03-8 Show GitHub Exploit DB Packet Storm
195176 6.1 警告
Network
MantisBT Group - MantisBT の bug_change_status_page.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6797 2017-03-30 15:39 2017-03-7 Show GitHub Exploit DB Packet Storm
195177 9.8 緊急
Network
Canonical
click project
- click の install.py における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-8768 2017-03-30 15:39 2015-10-15 Show GitHub Exploit DB Packet Storm
195178 9.8 緊急
Network
NetComm Wireless Limited. - NetCommWireless HSPA 3G10WVE Wireless Router のファームウェアの ping.cgi における任意のコマンドを実行される脆弱性 CWE-77
コマンドインジェクション
CVE-2015-6024 2017-03-30 15:31 2015-09-3 Show GitHub Exploit DB Packet Storm
195179 7.3 重要
Network
NetComm Wireless Limited. - NetCommWireless HSPA 3G10WVE Wireless Router のファームウェアの ping.cgi におけるアクセス制限を回避される脆弱性 CWE-284
不適切なアクセス制御
CVE-2015-6023 2017-03-30 15:31 2015-09-3 Show GitHub Exploit DB Packet Storm
195180 6.7 警告
Local
DELL EMC (旧 EMC Corporation) - EMC RecoverPoint および RecoverPoint for Virtual Machines におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2016-6649 2017-03-30 15:25 2016-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1141 4.3 MEDIUM
Network
jenkins azure_ad Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. CWE-601
Open Redirect
CVE-2026-42525 2026-05-5 23:25 2026-04-29 Show GitHub Exploit DB Packet Storm
1142 8.8 HIGH
Network
agilonhealth minerva An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their … CWE-285
Improper Authorization
CVE-2026-5781 2026-05-5 23:24 2026-04-28 Show GitHub Exploit DB Packet Storm
1143 8.1 HIGH
Network
agilonhealth minerva An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authentic… CWE-284
Improper Access Control
CVE-2026-5780 2026-05-5 23:22 2026-04-28 Show GitHub Exploit DB Packet Storm
1144 5.5 MEDIUM
Local
canonical pdfunite PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen… CWE-120
Classic Buffer Overflow
CVE-2018-25306 2026-05-5 23:22 2026-04-30 Show GitHub Exploit DB Packet Storm
1145 8.8 HIGH
Network
agilonhealth minerva An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the inf… CWE-284
Improper Access Control
CVE-2026-5779 2026-05-5 23:20 2026-04-28 Show GitHub Exploit DB Packet Storm
1146 9.8 CRITICAL
Network
- - A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-bas… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-7834 2026-05-5 23:16 2026-05-5 Show GitHub Exploit DB Packet Storm
1147 - - - In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. CWE-125
Out-of-bounds Read
CVE-2026-6918 2026-05-5 23:16 2026-05-5 Show GitHub Exploit DB Packet Storm
1148 7.5 HIGH
Network
- - The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3.4.11 due to insufficient escaping on the user supplied … CWE-89
SQL Injection
CVE-2026-4304 2026-05-5 23:16 2026-05-5 Show GitHub Exploit DB Packet Storm
1149 4.4 MEDIUM
Local
mercurycom mipc252w_firmware A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-35901 2026-05-5 22:41 2026-04-28 Show GitHub Exploit DB Packet Storm
1150 6.2 MEDIUM
Local
mercurycom mipc252w_firmware The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-35902 2026-05-5 22:40 2026-04-28 Show GitHub Exploit DB Packet Storm