Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 12:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197971 9.8 緊急
Network
Fedora Project
Apache Software Foundation
- Apache Xerces-C の XML パーサライブラリにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-0729 2016-11-21 16:18 2016-02-25 Show GitHub Exploit DB Packet Storm
197972 5 警告 PostgreSQL.org
Debian
Canonical
- PostgreSQL におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-0773 2016-11-21 16:18 2016-02-11 Show GitHub Exploit DB Packet Storm
197973 7.2 危険 Google
Linux
ヒューレット・パッカード・エンタープライズ
- Linux Kernel の security/keys/process_keys.c の join_session_keyring 関数における権限を取得される脆弱性 CWE-Other
その他
CVE-2016-0728 2016-11-21 16:18 2016-01-31 Show GitHub Exploit DB Packet Storm
197974 9.3 危険 レッドハット
日立
オラクル
- Oracle Java SE における Hotspot に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0636 2016-11-21 15:32 2016-03-23 Show GitHub Exploit DB Packet Storm
197975 5.9 警告
Network
OpenSSL Project
日立
- OpenSSL の SSLv2 の実装の s2_srvr.c のオラクル保護メカニズムにおける TLS 暗号文データを解読される脆弱性 CWE-200
情報漏えい
CVE-2016-0704 2016-11-21 15:32 2016-03-1 Show GitHub Exploit DB Packet Storm
197976 9.8 緊急
Network
Google
OpenSSL Project
オラクル
- OpenSSL の crypto/dsa/dsa_ameth.c の dsa_priv_decode 関数におけるメモリ二重解放の脆弱性 CWE-Other
その他
CVE-2016-0705 2016-11-21 15:32 2016-03-1 Show GitHub Exploit DB Packet Storm
197977 5.1 警告
Local
OpenSSL Project
日立
オラクル
- OpenSSL の crypto/bn/bn_exp.c の MOD_EXP_CTIME_COPY_FROM_PREBUF 関数における RSA の鍵を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-0702 2016-11-21 15:32 2016-03-1 Show GitHub Exploit DB Packet Storm
197978 4 警告 ヒューレット・パッカード
Debian
Canonical
Apache Software Foundation
- Apache Tomcat における SecurityManager の制限を回避される脆弱性 CWE-200
情報漏えい
CVE-2016-0706 2016-11-21 15:32 2016-01-5 Show GitHub Exploit DB Packet Storm
197979 10 危険 日立
Canonical
オラクル
- Oracle Java SE および Java SE Embedded における 2D に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0494 2016-11-21 15:32 2016-01-19 Show GitHub Exploit DB Packet Storm
197980 10 危険 日立
Canonical
オラクル
- 複数の Oracle Java 製品における AWT に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0483 2016-11-21 15:32 2016-01-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 3.5 LOW
Network
- - HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentio… New CWE-1230
 Exposure of Sensitive Information Through Metadata
CVE-2025-31959 2026-05-7 00:16 2026-05-7 Show GitHub Exploit DB Packet Storm
122 2.6 LOW
Network
- - HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data. New CWE-352
 Origin Validation Error
CVE-2025-31957 2026-05-7 00:16 2026-05-7 Show GitHub Exploit DB Packet Storm
123 6.1 MEDIUM
Network
n8n n8n n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowi… New CWE-601
Open Redirect
CVE-2026-42230 2026-05-6 23:57 2026-05-5 Show GitHub Exploit DB Packet Storm
124 8.8 HIGH
Network
n8n n8n n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be… New CWE-89
SQL Injection
CVE-2026-42229 2026-05-6 23:56 2026-05-5 Show GitHub Exploit DB Packet Storm
125 6.5 MEDIUM
Network
nginxui nginx_ui Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns the… New CWE-200
Information Exposure
CVE-2026-42223 2026-05-6 23:46 2026-05-5 Show GitHub Exploit DB Packet Storm
126 9.8 CRITICAL
Network
nginxui nginx_ui Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 1… New CWE-94
Code Injection
CVE-2026-42238 2026-05-6 23:45 2026-05-5 Show GitHub Exploit DB Packet Storm
127 6.5 MEDIUM
Network
- - FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to wri… New CWE-22
Path Traversal
CVE-2026-43975 2026-05-6 23:16 2026-05-6 Show GitHub Exploit DB Packet Storm
128 8.1 HIGH
Network
apache atlas Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can … New CWE-94
Code Injection
CVE-2026-40563 2026-05-6 23:16 2026-05-5 Show GitHub Exploit DB Packet Storm
129 6.6 MEDIUM
Local
- - Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability… New CWE-94
Code Injection
CVE-2026-35255 2026-05-6 23:16 2026-05-6 Show GitHub Exploit DB Packet Storm
130 6.1 MEDIUM
Local
- - Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with netw… New CWE-22
Path Traversal
CVE-2026-35254 2026-05-6 23:16 2026-05-6 Show GitHub Exploit DB Packet Storm