Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197971 7.5 重要
Network
マイクロソフト - 複数の Microsoft Windows 製品におけるセキュアブート保護メカニズムを回避される脆弱性 CWE-Other
その他
CVE-2016-7247 2016-11-15 11:35 2016-11-8 Show GitHub Exploit DB Packet Storm
197972 8.8 重要
Network
マイクロソフト - Microsoft SQL Server における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-7254 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197973 8.8 重要
Network
マイクロソフト - Microsoft SQL Server の SQL Server Agent における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-7253 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197974 6.5 警告
Network
マイクロソフト - Microsoft SQL Server における権限昇格の脆弱性 CWE-200
情報漏えい
CVE-2016-7252 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197975 6.1 警告
Network
マイクロソフト - Microsoft SQL Server の MDS API におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-7251 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197976 8.8 重要
Network
マイクロソフト - Microsoft SQL Server における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-7250 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197977 8.8 重要
Network
マイクロソフト - Microsoft SQL Server における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-7249 2016-11-15 11:24 2016-11-8 Show GitHub Exploit DB Packet Storm
197978 8.8 重要
Network
マイクロソフト - 複数の Microsoft Windows 製品のメディア ファンデーションにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-7217 2016-11-15 10:49 2016-11-8 Show GitHub Exploit DB Packet Storm
197979 6.5 警告
Network
マイクロソフト - 複数の Microsoft Windows 製品の atmfd.dll におけるプロセスメモリから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-7210 2016-11-15 10:49 2016-11-8 Show GitHub Exploit DB Packet Storm
197980 8.8 重要
Network
マイクロソフト - 複数の Microsoft Windows 製品のアニメーション マネージャーにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-7205 2016-11-15 10:48 2016-11-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
181 7.5 HIGH
Network
u-speed n300_firmware U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication… Update CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-36959 2026-05-5 12:00 2026-05-1 Show GitHub Exploit DB Packet Storm
182 5.4 MEDIUM
Network
redhat build_of_keycloak When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully func… Update CWE-425
NVD-CWE-noinfo
 Direct Request ('Forced Browsing')
CVE-2026-7500 2026-05-5 12:00 2026-05-1 Show GitHub Exploit DB Packet Storm
183 7.5 HIGH
Network
dbitnet dbit_n300_t1_pro_firmware Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent … Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-36957 2026-05-5 11:59 2026-05-1 Show GitHub Exploit DB Packet Storm
184 5.5 MEDIUM
Local
redhat multicluster_engine_for_kubernetes A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-sco… Update CWE-312
 Cleartext Storage of Sensitive Information
CVE-2026-7163 2026-05-5 11:57 2026-04-30 Show GitHub Exploit DB Packet Storm
185 7.8 HIGH
Local
qt qtdeclarative Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution… Update CWE-20
CWE-94
 Improper Input Validation 
Code Injection
CVE-2025-14576 2026-05-5 11:57 2026-04-30 Show GitHub Exploit DB Packet Storm
186 5.9 MEDIUM
Network
perldancer dancer\ Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the proce… Update CWE-338
CWE-340
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
 Generation of Predictable Numbers or Identifiers
CVE-2026-5080 2026-05-5 11:54 2026-04-30 Show GitHub Exploit DB Packet Storm
187 5.3 MEDIUM
Network
asrmicro asr1901_firmware
asr1903_firmware
NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/s… Update CWE-476
 NULL Pointer Dereference
CVE-2026-42800 2026-05-5 11:54 2026-04-30 Show GitHub Exploit DB Packet Storm
188 9.8 CRITICAL
Network
asrmicro asr1803_firmware Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects … Update CWE-125
Out-of-bounds Read
CVE-2026-42799 2026-05-5 11:53 2026-04-30 Show GitHub Exploit DB Packet Storm
189 9.8 CRITICAL
Network
oppo coloros_assistant ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. Update CWE-23
CWE-22
 Relative Path Traversal
Path Traversal
CVE-2026-22070 2026-05-5 11:53 2026-04-30 Show GitHub Exploit DB Packet Storm
190 7.5 HIGH
Network
4d server Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adja… Update CWE-611
XXE
CVE-2024-39847 2026-05-5 11:51 2026-04-30 Show GitHub Exploit DB Packet Storm