Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203851 7.8 重要
Local
Debian
Canonical
Spice Project
レッドハット
- SPICE におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-5260 2016-06-8 12:26 2015-10-6 Show GitHub Exploit DB Packet Storm
203852 9.8 緊急
Network
Debian
FreeType Project
- FreeType の複数の関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-9746 2016-06-8 12:08 2014-01-23 Show GitHub Exploit DB Packet Storm
203853 7.8 重要
Local
シスコシステムズ - Cisco IP Phone 8800 のソフトウェアにおける OS コマンド実行の権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1403 2016-06-7 18:18 2016-06-3 Show GitHub Exploit DB Packet Storm
203854 8.8 重要
Network
シスコシステムズ - Cisco Prime Network Analysis Module および Prime Virtual Network Analysis Module における任意の OS コマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1391 2016-06-7 18:18 2016-06-1 Show GitHub Exploit DB Packet Storm
203855 6.7 警告
Local
DELL EMC (旧 EMC Corporation) - EMC Isilon OneFS における root のシェルへのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0908 2016-06-7 17:12 2016-06-2 Show GitHub Exploit DB Packet Storm
203856 - - Apache Software Foundation - ** 削除 ** Apache Cordova Android におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5256 2016-06-7 14:04 2015-11-20 Show GitHub Exploit DB Packet Storm
203857 7.2 危険 GNU Project
Debian
Canonical
- Debian jessie の glibc パッケージおよび Ubuntu の elibc ならびに glibcc パッケージの pt_chown におけるキーストロークをキャプチャされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2856 2016-06-6 18:03 2016-02-16 Show GitHub Exploit DB Packet Storm
203858 5.9 警告
Network
Samba Project - Samba の SMB1 プロトコルの実装における SMB サーバになりすまされる脆弱性 CWE-Other
その他
CVE-2016-2114 2016-06-6 16:55 2016-04-12 Show GitHub Exploit DB Packet Storm
203859 7.4 重要
Network
Samba Project - Samba における LDAPS および HTTPS サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2016-2113 2016-06-6 16:54 2016-04-12 Show GitHub Exploit DB Packet Storm
203860 7.5 重要
Network
シスコシステムズ - Cisco IOS XR におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-1407 2016-06-6 16:34 2016-05-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
991 8.8 HIGH
Network
- - Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager… Update CWE-94
Code Injection
CVE-2021-47964 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
992 7.5 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-ad… Update CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-44826 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
993 - - - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3. Update CWE-79
Cross-site Scripting
CVE-2026-45616 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
994 8.1 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator t… Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46407 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
995 7.6 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter … Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46408 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
996 6.4 MEDIUM
Network
- - Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… Update CWE-79
Cross-site Scripting
CVE-2020-37237 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
997 6.4 MEDIUM
Network
- - CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… Update CWE-79
Cross-site Scripting
CVE-2020-37238 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
998 5.3 MEDIUM
Network
- - bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can… Update CWE-352
 Origin Validation Error
CVE-2020-37241 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
999 5.4 MEDIUM
Network
- - CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality… Update CWE-79
Cross-site Scripting
CVE-2021-47955 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1000 8.8 HIGH
Network
- - TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can… Update CWE-352
 Origin Validation Error
CVE-2021-47976 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm