Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196981 7.3 重要
Local
IBM - IBM Tivoli Storage Manager FastBack インストーラにおけるシステム上で任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-5934 2017-03-2 17:06 2016-08-22 Show GitHub Exploit DB Packet Storm
196982 4.7 警告
Local
IBM - IBM Tivoli Storage Manager HSM for Windows における暗号化された Tivoli Storage Manager パスワードを表示される脆弱性 CWE-200
情報漏えい
CVE-2016-5918 2017-03-2 17:06 2016-08-17 Show GitHub Exploit DB Packet Storm
196983 4.7 警告
Local
IBM - IBM Tivoli Storage Manager におけるパスワードが平文で公開される脆弱性 CWE-200
情報漏えい
CVE-2016-0371 2017-03-2 17:06 2016-11-2 Show GitHub Exploit DB Packet Storm
196984 5.5 警告
Local
IBM - IBM Security Access Manager アプライアンスにおける設定ファイルにアクセスされる脆弱性 CWE-200
情報漏えい
CVE-2015-5013 2017-03-2 16:54 2015-06-24 Show GitHub Exploit DB Packet Storm
196985 5.5 警告
Local
IBM - IBM Security Directory Server の Web 管理ツールにおけるツールのクラッシュを引き起こすコマンドを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2015-1976 2017-03-2 16:54 2015-02-19 Show GitHub Exploit DB Packet Storm
196986 4.4 警告
Local
IBM - IBM WebSphere eXtreme Scale および WebSphere DataPower XC10 アプライアンスにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-7418 2017-03-2 16:31 2015-09-29 Show GitHub Exploit DB Packet Storm
196987 6.1 警告
Network
IBM - IBM InfoSphere DataStage におけるクロスフレームスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9000 2017-03-2 16:14 2016-10-25 Show GitHub Exploit DB Packet Storm
196988 5.4 警告
Network
IBM - IBM Tivoli Storage Productivity Center におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-8943 2017-03-2 16:07 2016-12-13 Show GitHub Exploit DB Packet Storm
196989 3.1
Network
IBM - IBM Tivoli Storage Productivity Center におけるサーバの限定的なプロパティセットを編集される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-8942 2017-03-2 16:06 2016-12-13 Show GitHub Exploit DB Packet Storm
196990 8.8 重要
Network
IBM - IBM Tivoli Storage Productivity Center におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-8941 2017-03-2 16:06 2016-12-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
721 6.5 MEDIUM
Network
- - kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the k… Update CWE-943
 Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-42316 2026-05-14 01:53 2026-05-12 Show GitHub Exploit DB Packet Storm
722 6.1 MEDIUM
Network
- - fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. T… New CWE-91
Blind XPath Injection
CVE-2026-44665 2026-05-14 01:53 2026-05-14 Show GitHub Exploit DB Packet Storm
723 6.2 MEDIUM
Local
- - Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and … Update CWE-190
 Integer Overflow or Wraparound
CVE-2026-42199 2026-05-14 01:52 2026-05-9 Show GitHub Exploit DB Packet Storm
724 6.5 MEDIUM
Network
- - FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_mes… Update CWE-369
 Divide By Zero
CVE-2026-42209 2026-05-14 01:52 2026-05-9 Show GitHub Exploit DB Packet Storm
725 - - - Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts, and 2.17.0, the generated authentication filter … Update CWE-200
Information Exposure
CVE-2026-42333 2026-05-14 01:52 2026-05-10 Show GitHub Exploit DB Packet Storm
726 7.9 HIGH
Local
- - Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when … Update CWE-200
CWE-312
Information Exposure
 Cleartext Storage of Sensitive Information
CVE-2026-41520 2026-05-14 01:49 2026-05-9 Show GitHub Exploit DB Packet Storm
727 - - - Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e… Update CWE-190
CWE-787
 Integer Overflow or Wraparound
 Out-of-bounds Write
CVE-2026-42311 2026-05-14 01:49 2026-05-9 Show GitHub Exploit DB Packet Storm
728 - - - Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without… Update CWE-862
 Missing Authorization
CVE-2026-42461 2026-05-14 01:49 2026-05-9 Show GitHub Exploit DB Packet Storm
729 - - - Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerato… Update CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-42206 2026-05-14 01:49 2026-05-9 Show GitHub Exploit DB Packet Storm
730 7.6 HIGH
Network
- - ipl/web is a set of common web components for php projects. Prior to version 0.13.1, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the conte… Update CWE-79
Cross-site Scripting
CVE-2026-42224 2026-05-14 01:49 2026-05-9 Show GitHub Exploit DB Packet Storm