Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 2:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197721 5.4 警告
Network
IBM - IBM Tivoli Storage Productivity Center におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-8943 2017-03-2 16:07 2016-12-13 Show GitHub Exploit DB Packet Storm
197722 3.1
Network
IBM - IBM Tivoli Storage Productivity Center におけるサーバの限定的なプロパティセットを編集される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-8942 2017-03-2 16:06 2016-12-13 Show GitHub Exploit DB Packet Storm
197723 8.8 重要
Network
IBM - IBM Tivoli Storage Productivity Center におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-8941 2017-03-2 16:06 2016-12-13 Show GitHub Exploit DB Packet Storm
197724 6.8 警告
Network
IBM - IBM Tivoli Storage Manager for Virtual Environments における高い権限のユーザへ Windows ドメインの認証情報を公開される脆弱性 CWE-200
情報漏えい
CVE-2016-6034 2017-03-2 16:06 2016-12-12 Show GitHub Exploit DB Packet Storm
197725 7.8 重要
Local
IBM - IBM Tivoli Storage Manager の AIX クライアントにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-5985 2017-03-2 16:06 2016-11-10 Show GitHub Exploit DB Packet Storm
197726 7.5 重要
Network
IBM - IBM WebSphere Application Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-8919 2017-03-2 15:08 2016-10-25 Show GitHub Exploit DB Packet Storm
197727 8.8 重要
Network
IBM - IBM FileNet Workplace XT における任意のファイルをアップロードされる脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2016-8921 2017-03-2 14:45 2016-11-23 Show GitHub Exploit DB Packet Storm
197728 7.5 重要
Network
IBM - IBM UrbanCode Deploy における Agent Relay ActiveMQ Broker JMX インターフェースにアクセスされる脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-9008 2017-03-2 14:41 2016-12-8 Show GitHub Exploit DB Packet Storm
197729 10 緊急
Network
IBM - IBM UrbanCode Deploy におけるコードを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-8938 2017-03-2 14:41 2016-11-28 Show GitHub Exploit DB Packet Storm
197730 7.5 重要
Network
IBM - IBM UrbanCode Deploy における API および CLI の getResource のセキュアなロールプロパティにアクセスされる脆弱性 CWE-200
情報漏えい
CVE-2016-6068 2017-03-2 14:41 2016-11-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1421 5.4 MEDIUM
Network
openedx openedx Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags … CWE-79
Cross-site Scripting
CVE-2026-42857 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1422 9.8 CRITICAL
Network
- - arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a … CWE-121
Stack-based Buffer Overflow
CVE-2026-42854 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1423 - - - Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/acco… CWE-269
CWE-434
 Improper Privilege Management
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-42844 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1424 8.8 HIGH
Local
- - Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by s… CWE-15
CWE-269
CWE-732
 External Control of System or Configuration Setting
 Improper Privilege Management
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41489 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1425 - - - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-39806 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1426 - - - Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-39803 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1427 9.8 CRITICAL
Network
- - The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the un… CWE-88
Argument Injection
CVE-2026-31230 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1428 9.8 CRITICAL
Network
- - The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights f… CWE-502
 Deserialization of Untrusted Data
CVE-2026-31229 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1429 - - - Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review … CWE-863
 Incorrect Authorization
CVE-2026-2725 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1430 9.8 CRITICAL
Network
- - An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page. CWE-94
Code Injection
CVE-2025-65719 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm