Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202621 7.8 重要
Local
Google - Android の System_server で使用される Skia の include/core/SkPostConfig.h における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2412 2016-04-27 16:29 2016-04-4 Show GitHub Exploit DB Packet Storm
202622 5.3 警告
Network
Magento, Inc. - Magento Enterprise Edition および Community Edition の app/code/core/Mage/Rss/Helper/Order.php における重要な注文情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2212 2016-04-27 16:08 2016-02-23 Show GitHub Exploit DB Packet Storm
202623 8.1 重要
Network
Drupal
Debian
- Drupal の File モジュールにおけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2016-3162 2016-04-27 15:43 2016-02-24 Show GitHub Exploit DB Packet Storm
202624 8.1 重要
Network
Apache Software Foundation - Apache Camel における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2015-5348 2016-04-27 15:26 2015-11-12 Show GitHub Exploit DB Packet Storm
202625 8.4 重要
Local
NVIDIA - Windows 上で稼動する NVIDIA GPU グラフィックドライバのカーネルモードドライバレイヤの Escape インターフェースにおける重要な情報を取得される脆弱性 CWE-119
バッファエラー
CVE-2016-2558 2016-04-27 15:12 2016-03-14 Show GitHub Exploit DB Packet Storm
202626 8.4 重要
Local
NVIDIA - Windows 上で稼動する NVIDIA GPU グラフィックドライバのカーネルモードドライバレイヤの Escape インターフェースにおけるカーネルメモリから重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2557 2016-04-27 15:12 2016-03-14 Show GitHub Exploit DB Packet Storm
202627 5.3 警告
Network
OpenStack - OpenStack Compute の libvirt ドライバにおける任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-2140 2016-04-27 12:25 2016-03-8 Show GitHub Exploit DB Packet Storm
202628 6.2 警告
Local
FreeBSD - FreeBSD の sys/amd64/amd64/sys_machdep.c の amd64_set_ldt 関数における整数符号エラーの脆弱性 CWE-119
バッファエラー
CVE-2016-1885 2016-04-27 11:52 2016-03-16 Show GitHub Exploit DB Packet Storm
202629 7.5 重要
Network
OpenStack
レッドハット
- TripleO Heat templates におけるプライベートコンテナから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-5271 2016-04-27 11:36 2015-09-11 Show GitHub Exploit DB Packet Storm
202630 8.1 重要
Network
openSUSE project
SaltStack
- Salt における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-1866 2016-04-27 11:29 2016-01-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
951 9.6 CRITICAL
Network
- - URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 befor… New CWE-601
Open Redirect
CVE-2026-6795 2026-05-7 23:42 2026-05-7 Show GitHub Exploit DB Packet Storm
952 8.8 HIGH
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyD… New CWE-79
Cross-site Scripting
CVE-2026-5784 2026-05-7 23:42 2026-05-7 Show GitHub Exploit DB Packet Storm
953 9.6 CRITICAL
Network
- - Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. New CWE-352
 Origin Validation Error
CVE-2026-5791 2026-05-7 23:42 2026-05-7 Show GitHub Exploit DB Packet Storm
954 8.8 HIGH
Network
- - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affec… New CWE-80
Basic XSS
CVE-2026-6002 2026-05-7 23:42 2026-05-7 Show GitHub Exploit DB Packet Storm
955 7.7 HIGH
Network
openclaw openclaw OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interact… New CWE-862
 Missing Authorization
CVE-2026-43580 2026-05-7 23:41 2026-05-7 Show GitHub Exploit DB Packet Storm
956 9.6 CRITICAL
Adjacent
openclaw openclaw OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools proto… New CWE-1188
 Insecure Default Initialization of Resource
CVE-2026-43581 2026-05-7 23:41 2026-05-7 Show GitHub Exploit DB Packet Storm
957 9.1 CRITICAL
Network
x.org
redhat
x_server
enterprise_linux
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit … Update CWE-805
 Buffer Access with Incorrect Length Value
CVE-2026-34002 2026-05-7 23:39 2026-05-6 Show GitHub Exploit DB Packet Storm
958 8.1 HIGH
Network
google chrome Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security… New CWE-125
Out-of-bounds Read
CVE-2026-7981 2026-05-7 23:38 2026-05-7 Show GitHub Exploit DB Packet Storm
959 9.1 CRITICAL
Network
x.org
redhat
x_server
enterprise_linux
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an at… Update CWE-125
Out-of-bounds Read
CVE-2026-34000 2026-05-7 23:35 2026-05-6 Show GitHub Exploit DB Packet Storm
960 6.5 MEDIUM
Network
djangoproject django An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker … Update CWE-539
 Use of Persistent Cookies Containing Sensitive Information
CVE-2026-35192 2026-05-7 23:20 2026-05-6 Show GitHub Exploit DB Packet Storm