Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200841 7.2 危険 マイクロソフト - 複数の Microsoft Windows 製品のリモートデスクトッププロトコルの実装における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0036 2016-02-17 11:16 2016-02-9 Show GitHub Exploit DB Packet Storm
200842 5 警告 マイクロソフト - Microsoft .NET Framework におけるサービス運用妨害 (DoS) の脆弱性 CWE-94
コード・インジェクション
CVE-2016-0033 2016-02-17 11:16 2016-02-9 Show GitHub Exploit DB Packet Storm
200843 4.3 警告 マイクロソフト - Microsoft SharePoint Foundation 2013 の SharePoint Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-0039 2016-02-17 11:10 2016-02-9 Show GitHub Exploit DB Packet Storm
200844 9.3 危険 マイクロソフト - 複数の Microsoft Office 製品におけるクロスサイトスクリプティングの脆弱性 CWE-119
バッファエラー
CVE-2016-0022 2016-02-17 11:04 2016-02-9 Show GitHub Exploit DB Packet Storm
200845 7.2 危険 マイクロソフト - 複数の Microsoft 製品における権限昇格の脆弱性 CWE-Other
その他
CVE-2016-0041 2016-02-17 10:57 2016-02-9 Show GitHub Exploit DB Packet Storm
200846 5 警告 マイクロソフト - Microsoft Windows Server 2008 および 2012 のネットワーク ポリシー サーバーにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-0050 2016-02-17 10:39 2016-02-9 Show GitHub Exploit DB Packet Storm
200847 5 警告 マイクロソフト - Microsoft Windows Server 2012 の Active Directory フェデレーションサービスのフォームベース認証の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-0037 2016-02-17 10:38 2016-02-9 Show GitHub Exploit DB Packet Storm
200848 4 警告 MySQL AB
オラクル
- MySQL におけるサービス運用妨害 (mysqld のクラッシュ) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2749 2016-02-16 18:08 2012-08-17 Show GitHub Exploit DB Packet Storm
200849 10 危険 オラクル - Oracle Java SE における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3174 2016-02-16 18:07 2013-01-14 Show GitHub Exploit DB Packet Storm
200850 3.5 注意 MySQL AB
オラクル
- Oracle MySQL における Server Types の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-1548 2016-02-16 17:56 2013-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 7.2 HIGH
Network
- - A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow attacker to execute unauthorized code or commands v… New CWE-787
 Out-of-bounds Write
CVE-2026-40688 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
2 9.6 CRITICAL
Network
- - NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply … New CWE-20
CWE-22
 Improper Input Validation 
Path Traversal
CVE-2026-39399 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
3 7.2 HIGH
Network
- - BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) … New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-39387 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
4 8.0 HIGH
Network
- - nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting f… New CWE-1385
 Missing Origin Validation in WebSockets
CVE-2026-35589 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
5 6.5 MEDIUM
Network
- - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authent… New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-35034 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
6 - - - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions que… New CWE-88
CWE-862
Argument Injection
 Missing Authorization
CVE-2026-35033 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
7 - - - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not val… New CWE-73
CWE-918
 External Control of File Name or Path
Server-Side Request Forgery (SSRF) 
CVE-2026-35032 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
8 9.9 CRITICAL
Network
- - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field … New CWE-20
CWE-22
CWE-187
 Improper Input Validation 
Path Traversal
 Partial String Comparison
CVE-2026-35031 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
9 9.1 CRITICAL
Network
- - OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy… New CWE-290
 Authentication Bypass by Spoofing
CVE-2026-34457 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm
10 3.5 LOW
Physics
- - OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-i… New CWE-384
CWE-613
 Session Fixation
 Insufficient Session Expiration
CVE-2026-34454 2026-04-15 08:16 2026-04-15 Show GitHub Exploit DB Packet Storm