Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196831 7.5 重要
Network
YOOtheme - Pagekit CMS における登録ユーザのパスワードをリセットされる脆弱性 CWE-640
パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み
CVE-2017-5594 2017-02-9 14:15 2017-01-20 Show GitHub Exploit DB Packet Storm
196832 7.5 重要
Network
Quagga - Quagga の telnet 'vty' CLI における境界のないメモリを割り当てられる脆弱性 CWE-119
バッファエラー
CVE-2017-5495 2017-02-9 14:14 2017-01-23 Show GitHub Exploit DB Packet Storm
196833 8.1 重要
Network
TYPO3 Association - TYPO3 の Extbase における重要な情報を取得される脆弱性 CWE-254
セキュリティ機能
CVE-2016-5091 2017-02-9 14:12 2016-05-24 Show GitHub Exploit DB Packet Storm
196834 5.3 警告
Network
シスコシステムズ - Cisco WebEx Meetings Server における WebEx 管理サーバの完全修飾ドメイン名を表示される脆弱性 CWE-200
情報漏えい
CVE-2017-3797 2017-02-9 11:55 2017-01-18 Show GitHub Exploit DB Packet Storm
196835 7.2 重要
Network
シスコシステムズ - Cisco WebEx Meetings Server における他のホスト上の所定のシェルコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2017-3796 2017-02-9 11:55 2017-01-18 Show GitHub Exploit DB Packet Storm
196836 5.4 警告
Network
シスコシステムズ - Cisco WebEx Meetings Server における任意の非管理ユーザのパスワードを変更される脆弱性 CWE-255
証明書・パスワード管理
CVE-2017-3795 2017-02-9 11:55 2017-01-18 Show GitHub Exploit DB Packet Storm
196837 8.8 重要
Network
シスコシステムズ - Cisco WebEx Meetings Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-3794 2017-02-9 11:55 2017-01-18 Show GitHub Exploit DB Packet Storm
196838 6.1 警告
Network
シスコシステムズ - Cisco NetFlow Generation アプライアンスの Web ベースの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9222 2017-02-9 11:55 2016-11-16 Show GitHub Exploit DB Packet Storm
196839 7.5 重要
Network
Wireshark - Wireshark の DHCPv6 ディセクタにおける過度に大きなループを引き起こされる脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2017-5597 2017-02-9 11:14 2017-01-23 Show GitHub Exploit DB Packet Storm
196840 7.5 重要
Network
Wireshark - Wireshark の ASTERIX ディセクタにおける無限ループを引き起こされる脆弱性 CWE-835
無限ループ
CVE-2017-5596 2017-02-9 11:14 2017-01-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 7.1 HIGH
Network
- - New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an … New CWE-345
CWE-863
CWE-1188
 Insufficient Verification of Data Authenticity
 Incorrect Authorization
 Insecure Default Initialization of Resource
CVE-2026-41432 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
212 9.8 CRITICAL
Network
- - ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. New CWE-94
Code Injection
CVE-2026-36458 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
213 - - - Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal … New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-32686 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
214 9.8 CRITICAL
Network
- - The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports bot… New CWE-285
Improper Authorization
CVE-2026-30496 2026-05-9 08:16 2026-05-7 Show GitHub Exploit DB Packet Storm
215 8.8 HIGH
Adjacent
- - The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is con… New CWE-285
Improper Authorization
CVE-2026-30495 2026-05-9 08:16 2026-05-7 Show GitHub Exploit DB Packet Storm
216 6.1 MEDIUM
Network
- - Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb. New CWE-79
Cross-site Scripting
CVE-2025-67202 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
217 9.8 CRITICAL
Network
- - NPM package next-npm-version1.0.1 is vulnerable to Command injection. New CWE-94
Code Injection
CVE-2025-63706 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
218 9.8 CRITICAL
Network
- - npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). New CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2025-63703 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
219 7.5 HIGH
Network
- - Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. New - CVE-2026-42499 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
220 - - - Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially… New CWE-89
SQL Injection
CVE-2026-42287 2026-05-9 07:16 2026-05-9 Show GitHub Exploit DB Packet Storm