Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204701 4.3 警告
Network
Moodle - Moodle の mod/assign/externallib.php の save_submission 関数における提出期限の制限を回避される脆弱性 CWE-Other
その他
CVE-2016-2159 2016-05-26 17:26 2016-03-21 Show GitHub Exploit DB Packet Storm
204702 4.3 警告
Network
Moodle - Moodle の lib/ajax/getnavbranch.php におけるナビゲーションブランチから重要なカテゴリの詳細情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2158 2016-05-26 17:26 2016-03-21 Show GitHub Exploit DB Packet Storm
204703 8.8 重要
Network
Moodle - Moodle の mod/assign/adminmanageplugins.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-2157 2016-05-26 17:25 2016-03-21 Show GitHub Exploit DB Packet Storm
204704 4.3 警告
Network
Moodle - Moodle の calendar/externallib.php における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2156 2016-05-26 17:25 2016-03-21 Show GitHub Exploit DB Packet Storm
204705 4.3 警告
Network
Moodle - Moodle の Singleview の評定表機能における "Exclude grade" 設定を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2155 2016-05-26 17:22 2016-03-21 Show GitHub Exploit DB Packet Storm
204706 4.3 警告
Network
Moodle - Moodle の Event Monitor の admin/tool/monitor/lib.php における非表示のコース名を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2154 2016-05-26 17:22 2016-03-21 Show GitHub Exploit DB Packet Storm
204707 6.1 警告
Network
Moodle - Moodle の mod_data の拡張検索機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2153 2016-05-26 17:22 2016-03-21 Show GitHub Exploit DB Packet Storm
204708 6.1 警告
Network
Moodle - Moodle の auth/db/auth.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2152 2016-05-26 17:22 2016-03-21 Show GitHub Exploit DB Packet Storm
204709 4.3 警告
Network
Moodle - Moodle の user/index.php における生徒の電子メールアドレスを取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2151 2016-05-26 17:22 2016-03-21 Show GitHub Exploit DB Packet Storm
204710 7.8 重要
Local
Linux - Linux Kernel の net/tipc/socket.c の tipc_nl_publ_dump 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-4951 2016-05-26 15:23 2016-05-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
111 5.3 MEDIUM
Network
- - opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-45292 2026-05-29 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
112 - - - GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An a… New CWE-94
Code Injection
CVE-2026-45261 2026-05-29 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
113 7.5 HIGH
Network
- - opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics en… New CWE-755
 Improper Handling of Exceptional Conditions
CVE-2026-44902 2026-05-29 02:16 2026-05-28 Show GitHub Exploit DB Packet Storm
114 7.5 HIGH
Network
- - esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in… New CWE-22
Path Traversal
CVE-2026-44594 2026-05-29 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
115 8.7 HIGH
Network
- - Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in … New CWE-269
 Improper Privilege Management
CVE-2026-44543 2026-05-29 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
116 - - - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as t… New CWE-250
CWE-271
CWE-426
 Execution with Unnecessary Privileges
 Privilege Dropping / Lowering Errors
 Untrusted Search Path
CVE-2026-44477 2026-05-29 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
117 6.5 MEDIUM
Network
- - OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the … New CWE-89
SQL Injection
CVE-2026-38930 2026-05-29 02:16 2026-05-28 Show GitHub Exploit DB Packet Storm
118 7.3 HIGH
Network
- - An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php. New CWE-94
Code Injection
CVE-2026-37713 2026-05-29 02:16 2026-05-28 Show GitHub Exploit DB Packet Storm
119 7.3 HIGH
Network
- - An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in fun… New CWE-94
Code Injection
CVE-2026-37712 2026-05-29 02:16 2026-05-28 Show GitHub Exploit DB Packet Storm
120 8.0 HIGH
Network
- - An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-37266 2026-05-29 02:16 2026-05-28 Show GitHub Exploit DB Packet Storm