Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199741 7.8 重要
Local
Huawei - Huawei UTPS における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-2780 2016-04-28 12:28 2016-03-2 Show GitHub Exploit DB Packet Storm
199742 7.5 重要
Network
Huawei - 複数の Huawei 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-399
CVE-2015-8676 2016-04-28 12:28 2015-12-25 Show GitHub Exploit DB Packet Storm
199743 9.8 緊急
Network
Python Software Foundation - Pillow の libImaging/Resample.c の ImagingResampleHorizontal 関数における整数オーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4009 2016-04-28 12:06 2016-02-4 Show GitHub Exploit DB Packet Storm
199744 7.5 重要
Network
UNINETT
Fedora Project
- mod_auth_mellon の am_read_post_data 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-2146 2016-04-28 11:57 2016-03-9 Show GitHub Exploit DB Packet Storm
199745 7.5 重要
Network
UNINETT
Fedora Project
- mod_auth_mellon の am_read_post_data 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-2145 2016-04-28 11:57 2016-03-9 Show GitHub Exploit DB Packet Storm
199746 6.2 警告
Local
openSUSE project
LibTIFF
- LibTIFF の gif2tiff.c の readextension 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-3186 2016-04-28 11:02 2016-03-20 Show GitHub Exploit DB Packet Storm
199747 7.8 重要
Local
Xen プロジェクト - Linux Kernel の arch/x86/kernel/process_64.c の __switch_to 関数における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3157 2016-04-28 10:56 2016-03-16 Show GitHub Exploit DB Packet Storm
199748 5.5 警告
Local
Google - Android のフレームワークコンポーネントの server/content/ContentService.java における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2426 2016-04-28 09:50 2016-04-4 Show GitHub Exploit DB Packet Storm
199749 5.5 警告
Local
Google - Android の AOSP メールの mail/compose/ComposeActivity.java における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2425 2016-04-28 09:50 2016-04-4 Show GitHub Exploit DB Packet Storm
199750 5.5 警告
Local
Google - Android の SyncStorageEngine の server/content/SyncStorageEngine.java におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-2424 2016-04-28 09:50 2016-04-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 18, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
231 5.3 MEDIUM
Network
- - The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile… New CWE-863
 Incorrect Authorization
CVE-2026-24749 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
232 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoint… New CWE-89
SQL Injection
CVE-2026-33083 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
233 7.3 HIGH
Local
- - In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. New CWE-24
 Path Traversal: '../filedir'
CVE-2026-41082 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
234 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj en… New CWE-89
SQL Injection
CVE-2026-33084 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
235 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from… New CWE-89
SQL Injection
CVE-2026-33121 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
236 8.3 HIGH
Network
- - Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding spec… New CWE-1286
 Improper Validation of Syntactic Correctness of Input
CVE-2026-6442 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
237 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplie… New CWE-89
SQL Injection
CVE-2026-40900 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
238 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definitio… New CWE-89
SQL Injection
CVE-2026-33122 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
239 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql … New CWE-89
SQL Injection
CVE-2026-33207 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm
240 - - - DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mys… New CWE-183
 Permissive List of Allowed Inputs
CVE-2026-40899 2026-04-18 00:38 2026-04-17 Show GitHub Exploit DB Packet Storm