Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195191 9.8 緊急
Network
Aerospike, Inc. - Aerospike Database Server の RW ファブリックメッセージのパーティクルタイプにおける境界外インデックスに関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2016-9053 2017-03-9 16:49 2016-10-26 Show GitHub Exploit DB Packet Storm
195192 9.8 緊急
Network
Aerospike, Inc. - Aerospike Database Server のバッチ処理フィールドの構文解析機能における境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2016-9051 2017-03-9 16:49 2016-10-26 Show GitHub Exploit DB Packet Storm
195193 7.5 重要
Network
Aerospike, Inc. - Aerospike Database Server の Fabric_Worker コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-9049 2017-03-9 16:49 2016-10-26 Show GitHub Exploit DB Packet Storm
195194 7.8 重要
Local
JasPer Project
openSUSE project
Fedora Project
- JasPer の jas_stream.c の mem_close 関数におけるメモリ二重解放の脆弱性 CWE-415
二重解放
CVE-2016-8693 2017-03-9 16:03 2016-10-20 Show GitHub Exploit DB Packet Storm
195195 5.5 警告
Local
Debian
JasPer Project
Fedora Project
- JasPer の libjasper/jpc/jpc_dec.c の jpc_dec_process_siz 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-369
ゼロ除算
CVE-2016-8692 2017-03-9 16:03 2016-10-16 Show GitHub Exploit DB Packet Storm
195196 5.5 警告
Local
Debian
JasPer Project
Fedora Project
- JasPer の libjasper/jpc/jpc_dec.c の jpc_dec_process_siz 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-369
ゼロ除算
CVE-2016-8691 2017-03-9 16:03 2016-10-16 Show GitHub Exploit DB Packet Storm
195197 5 警告 アップル
日本電気
- 複数の Apple 製品の Secure Transport における EXPORT_RSA 暗号に対して暗号スイートのダウングレード攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2015-1067 2017-03-9 15:34 2015-03-9 Show GitHub Exploit DB Packet Storm
195198 7.8 危険 日本電気 - SSL/TLS の実装が輸出グレードの RSA 鍵を受け入れる問題 (FREAK 攻撃) CWE-Other
その他
- 2017-03-9 15:33 2015-03-6 Show GitHub Exploit DB Packet Storm
195199 4.3 警告 マイクロソフト
日本電気
- 複数の Microsoft Windows 製品の Schannel における EXPORT_RSA 暗号に対して暗号スイートのダウングレード攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2015-1637 2017-03-9 15:33 2015-03-5 Show GitHub Exploit DB Packet Storm
195200 4.3 警告 日本電気
アップル
サン・マイクロシステムズ
ヒューレット・パッカード
OpenSSL Project
オラクル
日立
- OpenSSL の s3_clnt.c の ssl3_get_key_exchange 関数における RSA-to-EXPORT_RSA ダウングレード攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2015-0204 2017-03-9 15:33 2015-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
401 10.0 CRITICAL
Network
- - A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request. New CWE-22
Path Traversal
CVE-2026-36767 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
402 - - - Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting … New - CVE-2026-36766 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
403 - - - An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload. New - CVE-2026-36765 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
404 5.0 MEDIUM
Network
- - A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request. New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-36764 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
405 6.1 MEDIUM
Network
- - A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted… New CWE-79
Cross-site Scripting
CVE-2026-36763 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
406 - - - An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary fi… New - CVE-2026-36762 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
407 6.1 MEDIUM
Network
- - A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into th… New CWE-79
Cross-site Scripting
CVE-2026-36761 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
408 9.6 CRITICAL
Network
- - An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files w… New CWE-22
Path Traversal
CVE-2026-36760 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
409 6.5 MEDIUM
Network
- - A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-36759 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
410 4.3 MEDIUM
Network
- - A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-36758 2026-05-1 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm