Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203131 7.3 重要
Network
Rockwell Automation - Rockwell Automation FactoryTalk EnergyMetrix におけるアクセス権を取得される脆弱性 CWE-Other
その他
CVE-2016-4531 2016-08-1 14:54 2016-07-26 Show GitHub Exploit DB Packet Storm
203132 9.8 緊急
Network
Rockwell Automation - Rockwell Automation FactoryTalk EnergyMetrix における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-4522 2016-08-1 14:54 2016-07-26 Show GitHub Exploit DB Packet Storm
203133 9.8 緊急
Network
ICU project - International Components for Unicode の common/uloc.cpp におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-6293 2016-08-1 14:12 2016-07-13 Show GitHub Exploit DB Packet Storm
203134 6.1 警告
Network
シーメンス - Siemens SINEMA Remote Connect Server の統合 Web サーバにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6204 2016-08-1 11:27 2016-07-22 Show GitHub Exploit DB Packet Storm
203135 7.5 重要
Network
シーメンス - Siemens SIMATIC NET PC ソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-5874 2016-08-1 11:27 2016-07-22 Show GitHub Exploit DB Packet Storm
203136 8.8 重要
Network
CA Technologies - CA eHealth におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2016-6152 2016-07-29 16:25 2016-07-21 Show GitHub Exploit DB Packet Storm
203137 8.8 重要
Network
CA Technologies - CA eHealth におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2016-6151 2016-07-29 16:25 2016-07-21 Show GitHub Exploit DB Packet Storm
203138 3.3
Local
eCryptfs.org
Canonical
- eCryptfs の ecryptfs-setup-swap における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2015-8946 2016-07-29 16:09 2015-08-4 Show GitHub Exploit DB Packet Storm
203139 3.3
Local
eCryptfs.org
Canonical
- eCryptfs の ecryptfs-setup-swap における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2016-6224 2016-07-29 16:09 2016-07-6 Show GitHub Exploit DB Packet Storm
203140 4.3 警告
Network
Google - Google Chrome で使用される Blink の CSP の実装の WebKit/Source/core/frame/csp/CSPSource.cpp における特定の HSTS Web サイトへのアクセスの有無を確認される脆弱性 CWE-200
情報漏えい
CVE-2016-5137 2016-07-29 15:16 2016-07-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2111 - - - Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL qu… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-42097 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
2112 - - - Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e… CWE-603
 Use of Client-Side Authentication
CVE-2026-42098 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
2113 - - - Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves… CWE-362
Race Condition
CVE-2026-42099 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
2114 - - - Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Clou… CWE-228
 Improper Handling of Syntactically Invalid Structure
CVE-2026-42100 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
2115 3.9 LOW
Local
- - FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app… CWE-79
Cross-site Scripting
CVE-2026-27964 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
2116 6.5 MEDIUM
Network
- - FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta… CWE-200
CWE-212
Information Exposure
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-27892 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
2117 5.3 MEDIUM
Network
- - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv… CWE-200
CWE-524
CWE-672
Information Exposure
 Use of Cache Containing Sensitive Information
 Operation on a Resource after Expiration or Release
CVE-2026-32244 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
2118 - - - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature… CWE-862
 Missing Authorization
CVE-2026-33514 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
2119 10.0 CRITICAL
Network
- - HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem… CWE-502
 Deserialization of Untrusted Data
CVE-2026-43633 2026-05-19 23:43 2026-05-19 Show GitHub Exploit DB Packet Storm
2120 6.5 MEDIUM
Network
vercel turborepo Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the l… CWE-352
CWE-384
 Origin Validation Error
 Session Fixation
CVE-2026-45773 2026-05-19 23:41 2026-05-16 Show GitHub Exploit DB Packet Storm