Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201221 5 警告 オラクル - Oracle E-Business Suite の Oracle Financial Consolidation Hub における Business Intelligence に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0538 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201222 6.4 警告 オラクル - Oracle E-Business Suite の Oracle Human Resources における Person に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0537 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201223 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Universal Work Queue における Error Messages に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0536 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201224 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Project Contracts における Printing に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0534 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201225 4.3 警告 オラクル - Oracle E-Business Suite の Oracle CRM Technical Foundation における Messaging に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0533 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201226 6.4 警告 オラクル - Oracle E-Business Suite の Oracle CRM Technical Foundation における Security Assignments に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0532 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201227 4 警告 オラクル - Oracle E-Business Suite の Oracle Applications Manager における Oracle Diagnostics Interfaces に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0531 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201228 6.4 警告 オラクル - Oracle E-Business Suite の Oracle Customer Interaction History における User GUI に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0530 2016-01-25 09:48 2016-01-19 Show GitHub Exploit DB Packet Storm
201229 6.4 警告 オラクル - Oracle E-Business Suite の Oracle Customer Interaction History における User GUI に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0529 2016-01-25 09:43 2016-01-19 Show GitHub Exploit DB Packet Storm
201230 6.4 警告 オラクル - Oracle E-Business Suite の Oracle Customer Interaction History における User GUI に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0528 2016-01-25 09:43 2016-01-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
41 6.4 MEDIUM
Network
- - The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2… New CWE-79
Cross-site Scripting
CVE-2026-6048 2026-04-18 14:16 2026-04-18 Show GitHub Exploit DB Packet Storm
42 6.4 MEDIUM
Network
- - The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insuffic… New CWE-79
Cross-site Scripting
CVE-2026-4801 2026-04-18 14:16 2026-04-18 Show GitHub Exploit DB Packet Storm
43 7.5 HIGH
Network
- - Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot… Update CWE-321
CWE-502
 Use of Hard-coded Cryptographic Key
 Deserialization of Untrusted Data
CVE-2026-5426 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
44 7.5 HIGH
Network
- - libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. Update CWE-331
 Insufficient Entropy
CVE-2026-41080 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
45 6.5 MEDIUM
Adjacent
- - An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio rang… Update CWE-284
Improper Access Control
CVE-2026-37100 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
46 7.5 HIGH
Network
- - JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade t… Update CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-31987 2026-04-18 13:16 2026-04-16 Show GitHub Exploit DB Packet Storm
47 9.8 CRITICAL
Network
- - SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE de… New CWE-787
 Out-of-bounds Write
CVE-2026-40494 2026-04-18 12:16 2026-04-18 Show GitHub Exploit DB Packet Storm
48 9.8 CRITICAL
Network
- - SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes… New CWE-787
 Out-of-bounds Write
CVE-2026-40493 2026-04-18 12:16 2026-04-18 Show GitHub Exploit DB Packet Storm
49 9.8 CRITICAL
Network
- - SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves… New CWE-787
 Out-of-bounds Write
CVE-2026-40492 2026-04-18 12:16 2026-04-18 Show GitHub Exploit DB Packet Storm
50 6.5 MEDIUM
Network
- - gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP… New CWE-22
Path Traversal
CVE-2026-40491 2026-04-18 12:16 2026-04-18 Show GitHub Exploit DB Packet Storm