Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199321 8.8 重要
Network
Google - Google Chrome で使用される Blink の V8 バインディングにおける同一生成元ポリシーを回避される脆弱性 CWE-Other
その他
CVE-2016-1668 2016-05-20 16:49 2016-05-11 Show GitHub Exploit DB Packet Storm
199322 8.8 重要
Network
Google - Google Chrome で使用される Blink の DOM の実装における同一生成元ポリシーを回避される脆弱性 CWE-Other
その他
CVE-2016-1667 2016-05-20 16:49 2016-05-11 Show GitHub Exploit DB Packet Storm
199323 6.5 警告
Network
IBM - IBM SPSS Statistics の ActiveX コントロールの Initialize 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-8530 2016-05-20 15:13 2015-12-8 Show GitHub Exploit DB Packet Storm
199324 9.8 緊急
Network
meteocontrol - 複数の meteocontrol WEB'log 製品における重要な平文情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2298 2016-05-20 14:58 2016-05-12 Show GitHub Exploit DB Packet Storm
199325 9.4 緊急
Network
meteocontrol - 複数の meteocontrol WEB'log 製品における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2016-2297 2016-05-20 14:58 2016-05-12 Show GitHub Exploit DB Packet Storm
199326 9.4 緊急
Network
meteocontrol - 複数の meteocontrol WEB'log 製品における重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2016-2296 2016-05-20 14:58 2016-05-12 Show GitHub Exploit DB Packet Storm
199327 5.5 警告
Local
ヒューレット・パッカード・エンタープライズ - HPE HP-UX 11iv3 上で稼動する Base-VxFS におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2016-2016 2016-05-20 14:53 2016-05-9 Show GitHub Exploit DB Packet Storm
199328 7.8 重要
Local
シマンテック - Symantec Endpoint Encryption の EEDService における権限を取得される脆弱性 CWE-Other
その他
CVE-2015-8156 2016-05-20 14:34 2015-11-13 Show GitHub Exploit DB Packet Storm
199329 7.8 重要
Local
Debian
OpenAFS
- OpenAFS の afs_pioctl.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2015-8312 2016-05-20 14:25 2015-12-16 Show GitHub Exploit DB Packet Storm
199330 4.9 警告
Network
Apache Software Foundation - Apache Ambari の File Browser View における任意のファイルを読まれる脆弱性 CWE-Other
その他
CVE-2016-0731 2016-05-20 14:02 2016-01-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
901 9.8 CRITICAL
Network
- - goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started w… CWE-306
Missing Authentication for Critical Function
CVE-2026-40884 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
902 - - - goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global ba… CWE-200
Information Exposure
CVE-2026-40885 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
903 6.5 MEDIUM
Network
- - Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting… CWE-284
Improper Access Control
CVE-2026-40888 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
904 6.5 MEDIUM
Network
- - Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Ver… CWE-284
Improper Access Control
CVE-2026-40889 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
905 7.5 HIGH
Network
- - The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > charact… CWE-125
Out-of-bounds Read
CVE-2026-40890 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
906 9.1 CRITICAL
Network
- - goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-40903 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
907 6.5 MEDIUM
Network
- - Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, al… CWE-89
SQL Injection
CVE-2026-41320 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
908 8.8 HIGH
Network
- - HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attacker… CWE-276
Incorrect Default Permissions 
CVE-2026-6819 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
909 8.8 HIGH
Network
- - A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker to execute arbitrary SQL queries against the backend database. The vulnerability is caused b… CWE-89
SQL Injection
CVE-2025-70420 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm
910 8.5 HIGH
Network
- - Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitab… CWE-284
Improper Access Control
CVE-2026-21997 2026-04-23 06:24 2026-04-22 Show GitHub Exploit DB Packet Storm