Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204201 6.1 警告
Network
アドビシステムズ - Adobe ColdFusion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1113 2016-05-17 18:11 2016-05-10 Show GitHub Exploit DB Packet Storm
204202 9.8 緊急
Network
SUSE - SUSE Linux Enterprise で使用される yast2-users における脆弱性 CWE-255
証明書・パスワード管理
CVE-2016-1601 2016-05-17 15:47 2016-04-25 Show GitHub Exploit DB Packet Storm
204203 5.9 警告
Network
GNU Project
Canonical
Fedora Project
- GNU Libtasn1 の lib/decoding.c の _asn1_extract_der_octet 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-4008 2016-05-17 14:52 2016-04-11 Show GitHub Exploit DB Packet Storm
204204 4.6 警告
Physics
Lexmark - Lexmark プリンタのファームウェアにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-3145 2016-05-17 14:52 2016-04-7 Show GitHub Exploit DB Packet Storm
204205 7.8 重要
Local
Linux - 32-bit プラットフォーム上で稼動する Linux Kernel の net/netfilter/x_tables.c における整数オーバーフローの脆弱性 CWE-189
CWE-Other
CVE-2016-3135 2016-05-17 14:51 2016-03-10 Show GitHub Exploit DB Packet Storm
204206 6.8 警告
Local
Google
Linux
- Debian wheezy の linux パッケージおよび Red Hat Enterprise Linux の kernel パッケージの特定の Linux Kernel バックポートの fs/pipe.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-0774 2016-05-17 14:51 2016-04-27 Show GitHub Exploit DB Packet Storm
204207 5.5 警告
Local
Linux - PowerPC プラットフォーム上で稼動する Linux Kernel の arch/powerpc/kernel/process.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2015-8845 2016-05-17 14:51 2015-11-19 Show GitHub Exploit DB Packet Storm
204208 5.5 警告
Local
Linux - PowerPC プラットフォーム上で稼動する Linux Kernel のシグナルの実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-8844 2016-05-17 14:51 2015-11-19 Show GitHub Exploit DB Packet Storm
204209 7.5 重要
Network
マカフィー - McAfee LiveSafe で使用される AV エンジンにおける整数符号エラーの脆弱性 CWE-20
不適切な入力確認
CVE-2016-4535 2016-05-17 14:26 2016-05-2 Show GitHub Exploit DB Packet Storm
204210 9.8 緊急
Network
トレンドマイクロ - Trend Micro Email Encryption Gateway の認証機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-4351 2016-05-17 14:26 2016-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
91 3.3 LOW
Local
- - Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web p… New CWE-357
 Insufficient UI Warning of Dangerous Operations
CVE-2026-47782 2026-05-22 01:08 2026-05-21 Show GitHub Exploit DB Packet Storm
92 - - - XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Ma… New CWE-23
 Relative Path Traversal
CVE-2026-23734 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
93 6.1 MEDIUM
Network
- - CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted … New CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-26028 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
94 - - - XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, … New CWE-862
 Missing Authorization
CVE-2026-33137 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
95 7.5 HIGH
Network
- - Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has… New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-47373 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
96 5.4 MEDIUM
Network
- - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue p… New CWE-79
Cross-site Scripting
CVE-2026-39960 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
97 7.5 HIGH
Network
- - nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademli… New CWE-252
 Unchecked Return Value
CVE-2026-40092 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
98 4.3 MEDIUM
Network
- - nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and s… New CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-40094 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
99 9.1 CRITICAL
Network
- - Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. New CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-47372 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm
100 - - - A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the … New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-9136 2026-05-22 01:04 2026-05-21 Show GitHub Exploit DB Packet Storm