Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198901 6.5 警告
Network
フォーティネット - Fortinet FortiWan の diagnosis_control.php ページにおける PCAP ファイルをダウンロードされる脆弱性 CWE-287
不適切な認証
CVE-2016-4966 2016-09-27 16:46 2016-09-7 Show GitHub Exploit DB Packet Storm
198902 8.8 重要
Network
フォーティネット - Fortinet FortiWan における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2016-4965 2016-09-27 16:45 2016-09-7 Show GitHub Exploit DB Packet Storm
198903 5.4 警告
Network
DELL EMC (旧 EMC Corporation) - EMC RSA Adaptive Authentication の Case Management アプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-0925 2016-09-27 15:51 2016-09-20 Show GitHub Exploit DB Packet Storm
198904 6.5 警告
Local
DELL EMC (旧 EMC Corporation) - EMC Avamar Server の Avamar Data Store および Avamar Virtual Edition における root アクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0921 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198905 7.8 重要
Local
DELL EMC (旧 EMC Corporation) - EMC Avamar Server の Avamar Data Store および Avamar Virtual Edition における root アクセス権を取得される脆弱性 CWE-Other
その他
CVE-2016-0920 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198906 9.8 緊急
Network
DELL EMC (旧 EMC Corporation) - 複数の EMC VNX 製品の SMB サービスにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0917 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198907 6.7 警告
Local
DELL EMC (旧 EMC Corporation) - EMC Avamar Server の Avamar Data Store および Avamar Virtual Edition における root 権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0905 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198908 8.6 重要
Network
DELL EMC (旧 EMC Corporation) - EMC Avamar Server の Avamar Data Store および Avamar Virtual Edition における暗号保護メカニズムを破られる脆弱性 CWE-200
CWE-310
CVE-2016-0904 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198909 9.1 緊急
Network
DELL EMC (旧 EMC Corporation) - EMC Avamar Server の Avamar Data Store および Avamar Virtual Edition におけるクライアントになりすまされる脆弱性 CWE-200
情報漏えい
CVE-2016-0903 2016-09-27 15:51 2016-09-19 Show GitHub Exploit DB Packet Storm
198910 8.6 重要
Network
- HPE Performance Center および LoadRunner におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2016-4384 2016-09-27 15:12 2016-09-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291 9.1 CRITICAL
Network
vmware spring_boot In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web applica… New CWE-862
 Missing Authorization
CVE-2026-40976 2026-04-30 22:54 2026-04-28 Show GitHub Exploit DB Packet Storm
292 6.7 MEDIUM
Local
vmware spring_boot When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is starte… New CWE-59
Link Following
CVE-2026-40977 2026-04-30 22:37 2026-04-28 Show GitHub Exploit DB Packet Storm
293 8.8 HIGH
Network
vmware spring_grpc When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the … New CWE-653
 Improper Isolation or Compartmentalization
CVE-2026-40968 2026-04-30 22:32 2026-04-29 Show GitHub Exploit DB Packet Storm
294 8.8 HIGH
Network
dlink dir-825m_firmware A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads … New CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7288 2026-04-30 22:27 2026-04-29 Show GitHub Exploit DB Packet Storm
295 5.3 MEDIUM
Network
vmware spring_grpc The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the a… New CWE-209
Information Exposure Through an Error Message
CVE-2026-40969 2026-04-30 22:24 2026-04-29 Show GitHub Exploit DB Packet Storm
296 8.8 HIGH
Network
dlink dir-825m_firmware A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer o… New CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7289 2026-04-30 22:19 2026-04-29 Show GitHub Exploit DB Packet Storm
297 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger … New CWE-408
 Incorrect Behavior Order: Early Amplification
CVE-2026-41374 2026-04-30 22:19 2026-04-29 Show GitHub Exploit DB Packet Storm
298 9.4 CRITICAL
Network
dlink di-8100_firmware A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffe… New CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7248 2026-04-30 22:18 2026-04-28 Show GitHub Exploit DB Packet Storm
299 4.3 MEDIUM
Network
- - VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cros… New CWE-352
 Origin Validation Error
CVE-2018-25310 2026-04-30 22:16 2026-04-30 Show GitHub Exploit DB Packet Storm
300 7.2 HIGH
Network
dlink di-8100_firmware A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation… New CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7247 2026-04-30 22:09 2026-04-28 Show GitHub Exploit DB Packet Storm