Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201201 6.8 警告 OpenSSL Project - OpenSSL の t1_lib.c 内の ssl_parse_serverhello_tlsext 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-362
競合状態
CVE-2014-3509 2016-10-7 11:49 2014-08-6 Show GitHub Exploit DB Packet Storm
201202 6.5 警告
Network
シスコシステムズ - Cisco FirePOWER Management Center の FireSIGHT システム ソフトウェアにおける認証チェックを回避される脆弱性 CWE-200
CWE-264
CVE-2016-6420 2016-10-6 17:47 2016-09-28 Show GitHub Exploit DB Packet Storm
201203 7.5 重要
Network
シスコシステムズ - Cisco FirePOWER Management Center における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-6419 2016-10-6 17:47 2016-09-28 Show GitHub Exploit DB Packet Storm
201204 7.5 重要
Network
IBM - IBM WebSphere Application Server および WebSphere Application Server Liberty における任意の Java コードを実行される脆弱性 CWE-Other
その他
CVE-2016-5983 2016-10-6 17:31 2016-09-22 Show GitHub Exploit DB Packet Storm
201205 5.4 警告
Network
IBM - IBM Business Process Manager Advanced のテストページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5901 2016-10-6 17:30 2016-09-30 Show GitHub Exploit DB Packet Storm
201206 8.6 重要
Network
American Auto-Matrix - American Auto-Matrix Aspect-Nexus および Aspect-Matrix Building Automation Front-End Solutions アプリケーションにおける重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2016-2308 2016-10-6 16:39 2016-09-29 Show GitHub Exploit DB Packet Storm
201207 7.5 重要
Network
Haxx
openSUSE project
- cURL および libcurl における TLS 接続の認証をハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2016-7141 2016-10-6 16:01 2016-08-22 Show GitHub Exploit DB Packet Storm
201208 6.5 警告
Network
Huawei - Huawei eSight におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-8280 2016-10-6 15:27 2016-09-28 Show GitHub Exploit DB Packet Storm
201209 7.5 重要
Network
Huawei - 複数の Huawei USG 製品のソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-8278 2016-10-6 15:27 2016-09-21 Show GitHub Exploit DB Packet Storm
201210 6.5 警告
Network
Huawei - 複数の Huawei USG 製品のソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-8277 2016-10-6 15:27 2016-09-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1491 7.5 HIGH
Network
- - When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software … CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-42920 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1492 8.7 HIGH
Network
- - An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions… CWE-78
OS Command 
CVE-2026-42924 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1493 5.8 MEDIUM
Network
- - When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the… CWE-172
 Encoding Error
CVE-2026-42926 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1494 8.7 HIGH
Network
- - When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have … CWE-35
 Path Traversal: '.../...//'
CVE-2026-42930 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1495 4.8 MEDIUM
Network
- - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar… CWE-125
Out-of-bounds Read
CVE-2026-42934 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1496 6.5 MEDIUM
Network
- - Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attack… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-42937 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1497 6.5 MEDIUM
Network
- - A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured… CWE-789
CWE-823
 Memory Allocation with Excessive Size Value
 Use of Out-of-range Pointer Offset
CVE-2026-42946 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1498 8.8 HIGH
Network
- - A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. CWE-78
OS Command 
CVE-2026-6281 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1499 8.1 HIGH
Network
- - A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to ot… CWE-22
Path Traversal
CVE-2026-6282 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm
1500 4.8 MEDIUM
Network
- - aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be ab… CWE-295
Improper Certificate Validation 
CVE-2026-8367 2026-05-14 01:27 2026-05-14 Show GitHub Exploit DB Packet Storm