Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
205811 7.5 重要
Network
日本電気 - CLUSTERPRO X におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-1145 2016-03-16 14:23 2016-01-29 Show GitHub Exploit DB Packet Storm
205812 7.1 重要
Network
株式会社コレガ - コレガ製の複数の無線 LAN ルータにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-1158 2016-03-16 13:45 2016-03-2 Show GitHub Exploit DB Packet Storm
205813 2.6 注意 ISC, Inc. - ISC BIND 9 Supported Preview Edition の rdataset.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-1284 2016-03-16 12:29 2016-01-26 Show GitHub Exploit DB Packet Storm
205814 6.6 警告 Google - Android のセットアップ ウィザードにおける Factory Reset Protection 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0813 2016-03-16 12:26 2016-02-1 Show GitHub Exploit DB Packet Storm
205815 6.6 警告 Google - Android のセットアップ ウィザードにおける Factory Reset Protection 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0812 2016-03-16 12:26 2016-02-1 Show GitHub Exploit DB Packet Storm
205816 7.8 危険 Google - Android の libmediaplayerservice の media/libmedia/ICrypto.cpp 関数における整数オーバーフローの脆弱性 CWE-200
情報漏えい
CVE-2016-0811 2016-03-16 12:15 2016-02-1 Show GitHub Exploit DB Packet Storm
205817 6.9 警告 Google - Android のメディアサーバの media/libmedia/SoundPool.cpp における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0810 2016-03-16 12:15 2016-02-1 Show GitHub Exploit DB Packet Storm
205818 8.3 危険 Google - Android の Wi-Fi の bcmdhd/wifi_hal/wifi_hal.cpp の wifi_cleanup 関数における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0809 2016-03-16 12:15 2016-02-1 Show GitHub Exploit DB Packet Storm
205819 4.9 警告 Google - Android の Minikin ライブラリの CmapCoverage.cpp の getCoverageFormat12 関数における整数オーバーフローの脆弱性 CWE-Other
その他
CVE-2016-0808 2016-03-16 12:15 2016-02-1 Show GitHub Exploit DB Packet Storm
205820 7.2 危険 Google - Android の Debuggerd の elf_utils.cpp の get_build_id 関数における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0807 2016-03-16 12:15 2016-02-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 6.1 MEDIUM
Local
- - An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content during installation. New CWE-346
 Origin Validation Error
CVE-2025-66592 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
212 6.1 MEDIUM
Local
- - An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content during installation. New CWE-346
 Origin Validation Error
CVE-2025-66593 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
213 6.2 MEDIUM
Local
- - A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local attackers to obtain sensitive informatio… New CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-2237 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
214 8.0 HIGH
Adjacent
- - A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and… New CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-3012 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
215 4.2 MEDIUM
Network
- - A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote at… New CWE-1288
 Improper Validation of Consistency within Input
CVE-2026-9689 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
216 7.1 HIGH
Network
- - A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem wri… New CWE-284
Improper Access Control
CVE-2026-1933 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
217 6.5 MEDIUM
Network
- - A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to i… New CWE-280
Improper Handling of Insufficient Permissions or Privileges 
CVE-2026-2340 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
218 6.8 MEDIUM
Network
- - A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token … New CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-9704 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
219 6.8 MEDIUM
Network
- - PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-an… New CWE-89
SQL Injection
CVE-2026-9617 2026-05-27 23:54 2026-05-27 Show GitHub Exploit DB Packet Storm
220 5.3 MEDIUM
Network
- - IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message … New CWE-209
Information Exposure Through an Error Message
CVE-2024-28765 2026-05-27 23:53 2026-05-27 Show GitHub Exploit DB Packet Storm