Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203271 7.5 重要
Network
Apache Software Foundation - Apache OpenMeetings の FileService.importFileByInternalUserId および FileService.importFile SOAP API メソッドにおける任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-2164 2016-04-18 17:37 2016-03-25 Show GitHub Exploit DB Packet Storm
203272 6.1 警告
Network
Apache Software Foundation - Apache OpenMeetings におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2163 2016-04-18 17:37 2016-03-25 Show GitHub Exploit DB Packet Storm
203273 6.1 警告
Network
Apache Software Foundation - Apache Struts におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2162 2016-04-18 17:36 2016-03-15 Show GitHub Exploit DB Packet Storm
203274 8.8 重要
Network
Apache Software Foundation - Apache Struts における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-0785 2016-04-18 17:36 2016-03-15 Show GitHub Exploit DB Packet Storm
203275 6.5 警告
Network
Apache Software Foundation - Apache OpenMeetings の Import/Export System Backups 機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-0784 2016-04-18 17:36 2016-03-25 Show GitHub Exploit DB Packet Storm
203276 7.5 重要
Network
Apache Software Foundation - Apache OpenMeetings の sendHashByUser 関数における任意のユーザのパスワードをリセットされる脆弱性 CWE-200
情報漏えい
CVE-2016-0783 2016-04-18 17:36 2016-03-25 Show GitHub Exploit DB Packet Storm
203277 7.8 重要
Local
Apache Software Foundation - Apache LDAP Studio および Apache Directory Studio の CSV エクスポートにおける任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2015-5349 2016-04-18 17:36 2015-07-1 Show GitHub Exploit DB Packet Storm
203278 6.2 警告
Local
openSUSE project
SUSE
- openSUSE および SUSE Linux Enterprise の MySQL Community Server パッケージおよび MariaDB パッケージにおけるデータベースの認証情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-5969 2016-04-18 17:22 2015-11-30 Show GitHub Exploit DB Packet Storm
203279 7.5 重要
Network
Huawei - 複数の Huawei Quidway スイッチ製品のソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-3678 2016-04-18 17:08 2016-03-30 Show GitHub Exploit DB Packet Storm
203280 6.4 警告
Adjacent
Huawei - Huawei E3276s USB モデムのソフトウェアにおけるネットワークトラフィックを傍受される脆弱性 CWE-Other
その他
CVE-2016-3676 2016-04-18 17:08 2016-03-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 8.6 HIGH
Network
- - 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object… New CWE-22
CWE-1321
Path Traversal
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-41690 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
412 8.6 HIGH
Network
- - i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled languag… New CWE-79
CWE-113
Cross-site Scripting
HTTP Response Splitting
CVE-2026-41683 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
413 6.4 MEDIUM
Network
- - Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style… New CWE-79
Cross-site Scripting
CVE-2026-41591 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
414 10.0 CRITICAL
Network
- - openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth… New CWE-287
Improper Authentication
CVE-2026-41070 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
415 6.3 MEDIUM
Network
- - In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), da… New CWE-282
 Improper Ownership Management
CVE-2026-40214 2026-05-9 01:16 2026-05-8 Show GitHub Exploit DB Packet Storm
416 7.4 HIGH
Network
- - OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless… New CWE-863
 Incorrect Authorization
CVE-2026-40213 2026-05-9 01:16 2026-05-8 Show GitHub Exploit DB Packet Storm
417 7.4 HIGH
Local
- - Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo… New CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-34354 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
418 - - - lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by o… New - CVE-2026-29975 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
419 - - - An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided buffer without a size parameter. Applications using minmea_scan o… New - CVE-2026-29974 2026-05-9 01:16 2026-05-9 Show GitHub Exploit DB Packet Storm
420 8.6 HIGH
Network
- - Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows un… New CWE-200
CWE-497
Information Exposure
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-42047 2026-05-9 01:08 2026-05-8 Show GitHub Exploit DB Packet Storm