Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204151 7.5 重要
Network
Kazu Yamamoto
Fedora Project
- pgpdump の buffer.c の read_binary 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-4021 2016-05-30 14:07 2016-04-13 Show GitHub Exploit DB Packet Storm
204152 6.1 警告
Network
フォーティネット - Fortinet FortiSandbox の Web ユーザインターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-7360 2016-05-30 13:43 2015-07-24 Show GitHub Exploit DB Packet Storm
204153 4.7 警告
Network
CMS Made Simple - CMS Made Simple におけるキャッシュポイズニング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2784 2016-05-30 13:37 2016-03-28 Show GitHub Exploit DB Packet Storm
204154 8.8 重要
Network
シスコシステムズ - Cisco Prime Infrastructure および Evolved Programmable Network Manager の API Web インターフェースにおける RBAC 制限を回避される脆弱性 CWE-Other
その他
CVE-2016-1406 2016-05-27 18:25 2016-05-23 Show GitHub Exploit DB Packet Storm
204155 7.5 重要
Network
シスコシステムズ - Cisco Identity Services Engine の Active Directory 統合コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-287
CVE-2016-1402 2016-05-27 18:25 2016-05-17 Show GitHub Exploit DB Packet Storm
204156 6.1 警告
Network
シスコシステムズ - Cisco Unified Computing System Central ソフトウェアの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1401 2016-05-27 18:25 2016-05-17 Show GitHub Exploit DB Packet Storm
204157 7.5 重要
Network
シスコシステムズ - Cisco TelePresence Video Communications Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-1400 2016-05-27 18:25 2016-05-16 Show GitHub Exploit DB Packet Storm
204158 7.5 重要
Network
シスコシステムズ - Cisco Web セキュリティ アプライアンスデバイス上で稼動する AsyncOS におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-1383 2016-05-27 18:25 2016-05-18 Show GitHub Exploit DB Packet Storm
204159 7.5 重要
Network
シスコシステムズ - Cisco Web セキュリティ アプライアンスデバイス上で稼動する AsyncOS におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-1382 2016-05-27 18:25 2016-05-18 Show GitHub Exploit DB Packet Storm
204160 7.5 重要
Network
シスコシステムズ - Cisco Web セキュリティ アプライアンスデバイス上で稼動する AsyncOS におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-1381 2016-05-27 18:25 2016-05-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
721 7.3 HIGH
Local
axis axis_os An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis d… CWE-1287
 Improper Validation of Specified Type of Input
CVE-2026-0802 2026-05-20 01:05 2026-05-12 Show GitHub Exploit DB Packet Storm
722 7.3 HIGH
Local
axis axis_os ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-0541 2026-05-20 00:40 2026-05-12 Show GitHub Exploit DB Packet Storm
723 6.1 MEDIUM
Network
- - Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an appli… CWE-79
Cross-site Scripting
CVE-2026-8656 2026-05-20 00:38 2026-05-16 Show GitHub Exploit DB Packet Storm
724 8.2 HIGH
Network
- - Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform pro… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-8657 2026-05-20 00:38 2026-05-16 Show GitHub Exploit DB Packet Storm
725 7.5 HIGH
Network
- - This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing,… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-8813 2026-05-20 00:38 2026-05-19 Show GitHub Exploit DB Packet Storm
726 5.3 MEDIUM
Network
- - Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in… CWE-409
 Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-8814 2026-05-20 00:38 2026-05-19 Show GitHub Exploit DB Packet Storm
727 9.8 CRITICAL
Network
microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CWE-20
CWE-94
CWE-119
 Improper Input Validation 
Code Injection
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-45495 2026-05-20 00:35 2026-05-19 Show GitHub Exploit DB Packet Storm
728 7.3 HIGH
Network
apache ofbiz Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.0… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-29226 2026-05-20 00:29 2026-05-19 Show GitHub Exploit DB Packet Storm
729 6.5 MEDIUM
Network
apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-31378 2026-05-20 00:29 2026-05-19 Show GitHub Exploit DB Packet Storm
730 6.1 MEDIUM
Network
apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of… CWE-22
CWE-79
CWE-94
Path Traversal
Cross-site Scripting
Code Injection
CVE-2026-31379 2026-05-20 00:27 2026-05-19 Show GitHub Exploit DB Packet Storm