Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196161 7.5 重要
Network
dnaTools, Inc. - dnaTools dnaLIMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2017-6527 2017-03-31 16:46 2017-03-8 Show GitHub Exploit DB Packet Storm
196162 9.8 緊急
Network
dnaTools, Inc. - dnaTools dnaLIMS における非認証のコマンドを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2017-6526 2017-03-31 16:45 2017-03-8 Show GitHub Exploit DB Packet Storm
196163 7.8 重要
Local
トレンドマイクロ - Trend Micro Endpoint Sensor における DLL ハイジャックの脆弱性 CWE-426
信頼性のない検索パス
CVE-2017-6798 2017-03-31 16:42 2017-03-7 Show GitHub Exploit DB Packet Storm
196164 5.9 警告
Network
DBD::mysql project - Perl 用 DBD::mysql モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-1249 2017-03-31 16:40 2016-11-15 Show GitHub Exploit DB Packet Storm
196165 5.5 警告
Local
partclone project - partclone の partclone.chkimg におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-6596 2017-03-31 16:35 2017-03-10 Show GitHub Exploit DB Packet Storm
196166 9.8 緊急
Network
DELL EMC (旧 EMC Corporation) - EMC Network Configuration Manager における不適切な認証の脆弱性 CWE-287
不適切な認証
CVE-2017-2768 2017-03-31 16:34 2017-02-1 Show GitHub Exploit DB Packet Storm
196167 9.8 緊急
Network
DELL EMC (旧 EMC Corporation) - EMC Network Configuration Manager における Java RMI にリモートでコードを実行される脆弱性 CWE-287
不適切な認証
CVE-2017-2767 2017-03-31 16:34 2017-02-1 Show GitHub Exploit DB Packet Storm
196168 6.7 警告
Local
General Electric Company - 複数の General Electric Proficy 製品におけるユーザパスワードを取得される脆弱性 CWE-200
情報漏えい
CVE-2016-9360 2017-03-31 16:25 2016-11-16 Show GitHub Exploit DB Packet Storm
196169 9.8 緊急
Network
マイクロソフト - Microsoft Skype における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-6517 2017-03-31 16:22 2017-03-15 Show GitHub Exploit DB Packet Storm
196170 5.5 警告
Local
virglrenderer project - virglrenderer の vrend_renderer.c の vrend_create_shader 関数における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2017-6355 2017-03-31 16:10 2017-02-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1411 - - - ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to pe… Update CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44499 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1412 5.3 MEDIUM
Network
- - novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend… Update CWE-22
Path Traversal
CVE-2026-42028 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1413 7.5 HIGH
Network
- - Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. Update CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-6659 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1414 - - - Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server co… Update CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-41517 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1415 9.1 CRITICAL
Network
- - Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verif… Update CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-42193 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1416 3.4 LOW
Network
- - draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAut… Update CWE-200
CWE-601
Information Exposure
Open Redirect
CVE-2026-42195 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1417 8.8 HIGH
Network
- - Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to i… Update CWE-284
CWE-639
Improper Access Control
 Authorization Bypass Through User-Controlled Key
CVE-2026-42205 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1418 - - - Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing un… Update CWE-352
 Origin Validation Error
CVE-2026-42286 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1419 - - - Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially… Update CWE-89
SQL Injection
CVE-2026-42287 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1420 4.9 MEDIUM
Network
- - Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but th… Update CWE-22
CWE-918
Path Traversal
Server-Side Request Forgery (SSRF) 
CVE-2026-41887 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm