Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
205871 6.8 警告 Google - Google Chrome の DOM の実装における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1623 2016-02-26 13:55 2016-02-9 Show GitHub Exploit DB Packet Storm
205872 6.8 警告 Google - Google Chrome の拡張サブシステムにおける同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1622 2016-02-26 13:55 2016-02-9 Show GitHub Exploit DB Packet Storm
205873 4.3 警告 シスコシステムズ - Cisco WebEx Meetings Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1309 2016-02-26 11:58 2016-02-5 Show GitHub Exploit DB Packet Storm
205874 2.1 注意 IBM - IBM WebSphere MQ の WMQ Telemetry の MQXR サービスにおける重要な情報を取得される脆弱性 CWE-200
CWE-255
CVE-2015-2012 2016-02-26 11:54 2015-02-19 Show GitHub Exploit DB Packet Storm
205875 4 警告 Roundcube.net - Roundcube の program/steps/addressbook/photo.inc における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2015-8794 2016-02-26 11:15 2015-06-5 Show GitHub Exploit DB Packet Storm
205876 6.8 警告 Mozilla Foundation - Mozilla Firefox における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1949 2016-02-26 11:02 2016-02-11 Show GitHub Exploit DB Packet Storm
205877 6.1 警告
Network
Script* - Log-Chat におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1157 2016-02-25 15:10 2016-02-22 Show GitHub Exploit DB Packet Storm
205878 4.3 警告 シスコシステムズ - Cisco Emergency Responder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1331 2016-02-25 14:56 2016-02-15 Show GitHub Exploit DB Packet Storm
205879 5 警告 シスコシステムズ - Cisco Universal Small Cell デバイスファームウェアにおける特定の証明書検証機能を回避される脆弱性 CWE-200
情報漏えい
CVE-2016-1321 2016-02-25 14:56 2016-02-12 Show GitHub Exploit DB Packet Storm
205880 6.8 警告 シスコシステムズ - Cisco Prime Collaboration の CLI における root として任意の OS コマンドを実行される脆弱性 CWE-264
CWE-78
CVE-2016-1320 2016-02-25 14:56 2016-02-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291 - - - Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() with… New CWE-59
Link Following
CVE-2026-42496 2026-05-26 11:16 2026-05-26 Show GitHub Exploit DB Packet Storm
292 - - - The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info conte… New CWE-80
Basic XSS
CVE-2025-71310 2026-05-26 11:16 2026-05-26 Show GitHub Exploit DB Packet Storm
293 7.3 HIGH
Network
- - A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student M… New CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9517 2026-05-26 09:16 2026-05-26 Show GitHub Exploit DB Packet Storm
294 5.4 MEDIUM
Network
webmin webmin Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attack… Update CWE-79
Cross-site Scripting
CVE-2026-22678 2026-05-26 09:16 2026-05-22 Show GitHub Exploit DB Packet Storm
295 8.5 HIGH
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elemen… New CWE-89
SQL Injection
CVE-2026-48837 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm
296 7.5 HIGH
Network
- - Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommer… New CWE-862
 Missing Authorization
CVE-2026-45438 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm
297 6.5 MEDIUM
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a thr… New CWE-79
Cross-site Scripting
CVE-2026-45435 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm
298 6.5 MEDIUM
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Ga… New CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-45217 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm
299 8.8 HIGH
Network
- - Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0. New CWE-266
 Incorrect Privilege Assignment
CVE-2026-45216 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm
300 7.5 HIGH
Network
- - Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a throug… New CWE-862
 Missing Authorization
CVE-2026-45209 2026-05-26 08:16 2026-05-26 Show GitHub Exploit DB Packet Storm