Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204311 7.8 重要
Local
IBM - Windows 上で稼動する IBM i Access における登録パスワードを取得される脆弱性 CWE-200
CWE-Other
CVE-2016-0287 2016-07-12 16:16 2016-06-28 Show GitHub Exploit DB Packet Storm
204312 8.2 重要
Local
IBM - IBM UrbanCode Deploy のエージェントにおける任意のエージェントへの root アクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0271 2016-07-12 16:16 2016-05-27 Show GitHub Exploit DB Packet Storm
204313 5.1 警告
Local
IBM - IBM Control Center および Sterling Control Center におけるマスターキーを復号される脆弱性 CWE-200
情報漏えい
CVE-2016-0252 2016-07-12 16:16 2016-06-24 Show GitHub Exploit DB Packet Storm
204314 6.8 警告
Physics
IBM - IBM Power Hardware Management Console における root アクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0230 2016-07-12 16:16 2016-06-29 Show GitHub Exploit DB Packet Storm
204315 - - トレンドマイクロ - ** 削除 ** Trend Micro Deep Discovery Inspector の hotfix_upload.cgi における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-5840 2016-07-12 15:14 2016-06-7 Show GitHub Exploit DB Packet Storm
204316 7.5 重要
Network
IBM - IBM WebSphere Application Server Liberty Profile の API Discovery の実装における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2945 2016-07-12 15:04 2016-06-21 Show GitHub Exploit DB Packet Storm
204317 7.5 重要
Network
IBM - IBM WebSphere Application Server Liberty Profile における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2923 2016-07-12 15:04 2016-06-29 Show GitHub Exploit DB Packet Storm
204318 5.3 警告
Network
IBM - IBM WebSphere Application Server Liberty Profile の Admin Center における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-0389 2016-07-12 15:04 2016-06-24 Show GitHub Exploit DB Packet Storm
204319 7.2 重要
Network
トレンドマイクロ - Deep Discovery Inspector において任意のコードが実行可能な脆弱性 CWE-noinfo
情報不足
CVE-2016-5840 2016-07-12 15:02 2016-06-16 Show GitHub Exploit DB Packet Storm
204320 7.5 重要
Network
Samba Project - Samba の libcli/smb/smbXcli_base.c におけるクライアント署名の保護メカニズムを回避される脆弱性 CWE-Other
その他
CVE-2016-2119 2016-07-12 11:51 2016-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1681 5.3 MEDIUM
Network
- - Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go c… - CVE-2026-9091 2026-05-30 05:16 2026-05-29 Show GitHub Exploit DB Packet Storm
1682 9.1 CRITICAL
Network
- - Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extra… - CVE-2026-9090 2026-05-30 05:16 2026-05-29 Show GitHub Exploit DB Packet Storm
1683 7.5 HIGH
Network
microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. CWE-502
 Deserialization of Untrusted Data
CVE-2026-41104 2026-05-30 04:46 2026-05-23 Show GitHub Exploit DB Packet Storm
1684 5.5 MEDIUM
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP me… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-48735 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1685 3.3 LOW
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams w… CWE-834
 Excessive Iteration
CVE-2026-48156 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1686 5.5 MEDIUM
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in l… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-48155 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1687 9.8 CRITICAL
Network
ibm engineering_lifecycle_management IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap… CWE-863
 Incorrect Authorization
CVE-2026-3660 2026-05-30 04:31 2026-05-27 Show GitHub Exploit DB Packet Storm
1688 9.6 CRITICAL
Network
amirraminfar dozzle Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepti… CWE-346
 Origin Validation Error
CVE-2026-44985 2026-05-30 04:30 2026-05-27 Show GitHub Exploit DB Packet Storm
1689 7.1 HIGH
Adjacent
free5gc free5gc free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it… CWE-358
 Improperly Implemented Security Check for Standard
CVE-2026-42081 2026-05-30 04:24 2026-05-28 Show GitHub Exploit DB Packet Storm
1690 8.6 HIGH
Network
amirraminfar dozzle Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is re… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45298 2026-05-30 04:23 2026-05-27 Show GitHub Exploit DB Packet Storm