Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197931 5.3 警告
Network
BlueZ Project - BlueZ の tools/parser/hci.c ソースファイルの le_meta_ev_dump 関数における境界外読み取りの脆弱性 CWE-119
CWE-125
CVE-2016-9803 2016-12-6 14:26 2016-11-14 Show GitHub Exploit DB Packet Storm
197932 5.3 警告
Network
BlueZ Project - BlueZ の monitor/packet.c ソースファイルの l2cap_packet 関数におけるバッファオーバーリードの脆弱性 CWE-119
バッファエラー
CVE-2016-9802 2016-12-6 14:26 2016-11-15 Show GitHub Exploit DB Packet Storm
197933 5.3 警告
Network
BlueZ Project - BlueZ の tools/parser/l2cap.c ソースファイルの set_ext_ctrl 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9801 2016-12-6 14:26 2016-11-14 Show GitHub Exploit DB Packet Storm
197934 5.3 警告
Network
BlueZ Project - BlueZ の tools/parser/hci.c ソースファイルの pin_code_reply_dump 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9800 2016-12-6 14:26 2016-11-14 Show GitHub Exploit DB Packet Storm
197935 5.3 警告
Network
BlueZ Project - BlueZ の btsnoop.c ソースファイルの pklg_read_hci 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9799 2016-12-6 14:26 2016-11-15 Show GitHub Exploit DB Packet Storm
197936 5.3 警告
Network
BlueZ Project - BlueZ の tools/parser/l2cap.c ソースファイルの conf_opt 関数における解放済みメモリ使用の脆弱性 CWE-416
解放済みメモリの使用
CVE-2016-9798 2016-12-6 14:26 2016-11-14 Show GitHub Exploit DB Packet Storm
197937 5.3 警告
Network
BlueZ Project - BlueZ の tools/parser/l2cap.c ソースファイルの l2cap_dump 関数におけるバッファオーバーリードの脆弱性 CWE-119
CWE-125
CVE-2016-9797 2016-12-6 14:26 2016-11-14 Show GitHub Exploit DB Packet Storm
197938 6.5 警告
Local
IBM - IBM PowerKVM の Linux Kernel コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
CWE-284
CVE-2016-3044 2016-12-6 11:29 2016-07-7 Show GitHub Exploit DB Packet Storm
197939 6.8 警告 Mozilla Foundation
openSUSE project
SUSE
オラクル
- Mozilla Firefox の dom/html/nsHTMLDocument.cpp における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-1961 2016-12-5 17:49 2016-03-8 Show GitHub Exploit DB Packet Storm
197940 6.8 警告 Mozilla Foundation
openSUSE project
SUSE
オラクル
- Mozilla Firefox の HTML5 文字列パーサの nsHtml5TreeBuilder クラスにおける整数アンダーフローの脆弱性 CWE-Other
その他
CVE-2016-1960 2016-12-5 17:49 2016-03-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
451 8.1 HIGH
Network
- - In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted… New CWE-89
SQL Injection
CVE-2026-44331 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
452 - - - Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-se… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40280 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
453 - - - PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when t… New CWE-502
CWE-918
 Deserialization of Untrusted Data
Server-Side Request Forgery (SSRF) 
CVE-2026-34084 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
454 - - - CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The l… New CWE-863
 Incorrect Authorization
CVE-2026-33489 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
455 - - - Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing … New CWE-862
 Missing Authorization
CVE-2026-33420 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
456 - - - SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided que… New CWE-89
SQL Injection
CVE-2026-33324 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
457 - - - CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decodi… New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-32936 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
458 - - - FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser control… New CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-32699 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
459 - - - Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink followin… New CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-31893 2026-05-6 05:16 2026-05-6 Show GitHub Exploit DB Packet Storm
460 8.1 HIGH
Network
- - School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data. Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-7491 2026-05-6 05:16 2026-05-2 Show GitHub Exploit DB Packet Storm