Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202851 4.3 警告 Apache Software Foundation - Apache Solr の Admin UI の webapp/web/js/scripts/schema-browser.js におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8796 2016-02-23 16:20 2015-08-16 Show GitHub Exploit DB Packet Storm
202852 4.3 警告 Apache Software Foundation - Apache Solr の Admin UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8795 2016-02-23 16:20 2015-04-6 Show GitHub Exploit DB Packet Storm
202853 4.3 警告 Roundcube.net - Roundcube の program/include/rcmail.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8793 2016-02-23 16:15 2015-06-5 Show GitHub Exploit DB Packet Storm
202854 6.1 警告 シスコシステムズ - Cisco Industrial Ethernet 2000 デバイス上で稼動する Cisco IOS におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-1330 2016-02-23 13:58 2016-02-15 Show GitHub Exploit DB Packet Storm
202855 10 危険 シスコシステムズ - Cisco RV220W デバイスの Web ベースの管理インターフェースにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-6319 2016-02-23 12:28 2015-08-17 Show GitHub Exploit DB Packet Storm
202856 4.3 警告 OpenJPEG project - OpenJPEG の opj_j2k_update_image_data 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-1923 2016-02-23 11:53 2016-01-18 Show GitHub Exploit DB Packet Storm
202857 4.3 警告
Network
マイクロソフト - Internet Explorer におけるクロスドメイン ポリシーを回避される脆弱性 CWE-Other
その他
CVE-2016-0069 2016-02-23 11:20 2016-02-19 Show GitHub Exploit DB Packet Storm
202858 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 から 11 における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0068 2016-02-23 11:11 2016-02-9 Show GitHub Exploit DB Packet Storm
202859 7.8 危険 アドビシステムズ - Adobe Experience Manager の Dispatcher におけるディスパッチャのルールを回避される脆弱性 CWE-noinfo
情報不足
CVE-2016-0957 2016-02-23 11:09 2016-02-9 Show GitHub Exploit DB Packet Storm
202860 10 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-0983 2016-02-23 10:26 2016-02-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
401 6.3 MEDIUM
Local
- - A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hard… New CWE-1241
 Use of Predictable Algorithm in Random Number Generator
CVE-2026-6420 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
402 3.1 LOW
Network
- - HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to exploit b… New CWE-80
Basic XSS
CVE-2025-59854 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
403 3.1 LOW
Network
- - HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the appl… New CWE-209
Information Exposure Through an Error Message
CVE-2025-59853 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
404 3.7 LOW
Network
- - HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise t… New CWE-319
Cleartext Transmission of Sensitive Information
CVE-2025-59852 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
405 3.7 LOW
Network
- - HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and … New - CVE-2025-59851 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
406 5.3 MEDIUM
Network
- - HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could al… New CWE-358
 Improperly Implemented Security Check for Standard
CVE-2025-31970 2026-05-6 20:16 2026-05-6 Show GitHub Exploit DB Packet Storm
407 5.2 MEDIUM
Local
- - There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traver… New CWE-269
 Improper Privilege Management
CVE-2026-40001 2026-05-6 19:16 2026-05-6 Show GitHub Exploit DB Packet Storm
408 8.8 HIGH
Network
- - A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server b… New CWE-94
Code Injection
CVE-2026-7841 2026-05-6 17:16 2026-05-6 Show GitHub Exploit DB Packet Storm
409 - - - The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized acti… New CWE-79
Cross-site Scripting
CVE-2026-23928 2026-05-6 17:16 2026-05-6 Show GitHub Exploit DB Packet Storm
410 - - - A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle datab… New CWE-522
 Insufficiently Protected Credentials
CVE-2026-23927 2026-05-6 17:16 2026-05-6 Show GitHub Exploit DB Packet Storm