Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206341 5 警告 アップル
OpenLDAP Foundation
- OpenLDAP の libraries/liblber/io.c の ber_get_next 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-6908 2016-01-19 16:59 2015-09-9 Show GitHub Exploit DB Packet Storm
206342 4.6 警告 ヒューレット・パッカード・エンタープライズ - 複数の HPE Network Switch のソフトウェアにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-6859 2016-01-19 16:19 2015-11-10 Show GitHub Exploit DB Packet Storm
206343 7.2 危険 ヒューレット・パッカード・エンタープライズ - 複数の HPE Network Switch のソフトウェアにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-6860 2016-01-19 16:19 2015-11-10 Show GitHub Exploit DB Packet Storm
206344 10 危険 Colorscore project - Ruby 用 Colorscore gem の lib/colorscore/histogram.rb の Histogram クラスの初期化メソッドにおける任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2015-7541 2016-01-19 11:05 2015-09-29 Show GitHub Exploit DB Packet Storm
206345 10 危険 アドバンテック株式会社 - Advantech EKI-132x デバイスのファームウェアにおける認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2015-7938 2016-01-19 10:49 2015-12-10 Show GitHub Exploit DB Packet Storm
206346 6.5 警告 アドバンテック株式会社 - Advantech WebAccess における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-3947 2016-01-19 10:49 2015-05-12 Show GitHub Exploit DB Packet Storm
206347 6.8 警告 アドバンテック株式会社 - Advantech WebAccess におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-3946 2016-01-19 10:49 2015-05-12 Show GitHub Exploit DB Packet Storm
206348 5 警告 アドバンテック株式会社 - Advantech WebAccess における電子メールプロジェクトアカウントについての重要な平文情報を読まれる脆弱性 CWE-200
情報漏えい
CVE-2015-3943 2016-01-19 10:49 2015-05-12 Show GitHub Exploit DB Packet Storm
206349 9.3 危険 Unitronics - Unitronics VisiLogic OPLC IDE におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-7939 2016-01-19 10:13 2015-11-12 Show GitHub Exploit DB Packet Storm
206350 4.3 警告 AVM - AVM FRITZ!OS の Push-Service-Mails 機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-7242 2016-01-18 15:22 2015-07-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
931 - - - Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr… CWE-330
CWE-331
CWE-338
 Use of Insufficiently Random Values
 Insufficient Entropy
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-42155 2026-05-19 04:35 2026-05-16 Show GitHub Exploit DB Packet Storm
932 7.1 HIGH
Local
- - Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.jso… CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-44641 2026-05-19 04:33 2026-05-16 Show GitHub Exploit DB Packet Storm
933 7.4 HIGH
Network
- - Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rgl… CWE-59
CWE-200
Link Following
Information Exposure
CVE-2026-45539 2026-05-19 04:33 2026-05-16 Show GitHub Exploit DB Packet Storm
934 - - - An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive… CWE-862
 Missing Authorization
CVE-2026-2031 2026-05-19 04:32 2026-05-16 Show GitHub Exploit DB Packet Storm
935 7.3 HIGH
Network
- - A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation cau… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-8725 2026-05-19 04:31 2026-05-17 Show GitHub Exploit DB Packet Storm
936 6.3 MEDIUM
Network
- - A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipu… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-8747 2026-05-19 04:31 2026-05-17 Show GitHub Exploit DB Packet Storm
937 7.3 HIGH
Network
- - A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of the file hiyoriUI.py of the component Model Handl… CWE-22
Path Traversal
CVE-2026-8755 2026-05-19 04:31 2026-05-17 Show GitHub Exploit DB Packet Storm
938 7.3 HIGH
Network
- - A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the comp… CWE-22
Path Traversal
CVE-2026-8756 2026-05-19 04:31 2026-05-17 Show GitHub Exploit DB Packet Storm
939 7.2 HIGH
Network
- - A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffe… CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-8764 2026-05-19 04:31 2026-05-18 Show GitHub Exploit DB Packet Storm
940 9.8 CRITICAL
Network
- - A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-8836 2026-05-19 04:26 2026-05-19 Show GitHub Exploit DB Packet Storm