Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
205801 8.3 危険 ネットギア - NETGEAR Management System NMS300 における任意の Java コードを実行される脆弱性 CWE-Other
その他
CVE-2016-1524 2016-03-24 18:08 2016-02-3 Show GitHub Exploit DB Packet Storm
205802 6.8 警告 IBM - IBM Mashup Center の Lotus Mashups コンポーネントにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-7407 2016-03-24 18:04 2015-11-20 Show GitHub Exploit DB Packet Storm
205803 6.8 警告 IBM - IBM Mashup Center の Lotus Mashups コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
CWE-Other
CVE-2015-7400 2016-03-24 18:03 2015-11-20 Show GitHub Exploit DB Packet Storm
205804 4.3 警告 アドビシステムズ
日立
- Adobe ColdFusion および LiveCycle Data Services で使用される Adobe BlazeDS における HTTP トラフィックをイントラネットサーバへ送信される脆弱性 CWE-20
不適切な入力確認
CVE-2015-5255 2016-03-24 17:24 2015-11-17 Show GitHub Exploit DB Packet Storm
205805 5 警告 アドビシステムズ
日立
- Adobe LiveCycle Data Services などの製品の flex-messaging-core.jar で使用される Apache Flex BlazeDS における任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2015-3269 2016-03-24 17:23 2015-08-18 Show GitHub Exploit DB Packet Storm
205806 6.8 警告 XZERES Wind Corp - XZERES 442SR Wind Turbines 上で稼働する XZERES 442SR OS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-0985 2016-03-24 17:23 2015-03-17 Show GitHub Exploit DB Packet Storm
205807 5.5 警告 Matt Johnston - Dropbear SSH における CRLF インジェクションの脆弱性 CWE-Other
その他
CVE-2016-3116 2016-03-24 11:22 2016-03-9 Show GitHub Exploit DB Packet Storm
205808 10 危険 ヒューレット・パッカード - HP Support Assistant における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2016-2245 2016-03-24 11:08 2016-03-7 Show GitHub Exploit DB Packet Storm
205809 10 危険 ヒューレット・パッカード・エンタープライズ - HPE Service Manager における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1998 2016-03-24 11:08 2016-03-21 Show GitHub Exploit DB Packet Storm
205810 10 危険 ヒューレット・パッカード・エンタープライズ - HPE Operations Orchestration および Operations Orchestration コンテンツにおける任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1997 2016-03-24 11:08 2016-03-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
751 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… New CWE-77
Command Injection
CVE-2026-38702 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
752 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… New CWE-77
Command Injection
CVE-2026-38703 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
753 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ve… New CWE-77
Command Injection
CVE-2026-38707 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
754 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlie… New CWE-77
Command Injection
CVE-2026-38704 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
755 8.6 HIGH
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st… New CWE-193
 Off-by-one Error
CVE-2026-49127 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
756 5.8 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allow… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-49129 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
757 5.3 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF by… New CWE-93
CRLF Injection
CVE-2026-49130 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
758 4.1 MEDIUM
Network
- - A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endp… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10052 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
759 2.7 LOW
Network
- - A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL que… New CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-10078 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
760 7.7 HIGH
Network
- - A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice tha… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42965 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm