Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206451 6.8 警告 アップル - Apple iOS および OS X の FontParser における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-6978 2015-12-16 17:48 2015-10-21 Show GitHub Exploit DB Packet Storm
206452 4.3 警告 シスコシステムズ - Cisco Model EPC3928 with EDVA デバイスの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-6402 2015-12-16 17:45 2015-12-8 Show GitHub Exploit DB Packet Storm
206453 7.5 危険 シスコシステムズ - Cisco Model EPC3928 with EDVA デバイスにおける認証要求を回避される脆弱性 CWE-287
不適切な認証
CVE-2015-6401 2015-12-16 17:40 2015-12-8 Show GitHub Exploit DB Packet Storm
206454 6.8 警告 シスコシステムズ - Cisco Model DPQ3925 with EDVA デバイスにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-6378 2015-12-16 16:44 2015-12-8 Show GitHub Exploit DB Packet Storm
206455 4.3 警告 シスコシステムズ - Cisco Small Business RV ルータおよび SA500 Security Appliance 上で稼動する乱数生成器における TLS 鍵ペアを特定される脆弱性 CWE-200
情報漏えい
CVE-2015-6418 2015-12-16 16:43 2015-12-10 Show GitHub Exploit DB Packet Storm
206456 4 警告 シスコシステムズ - Cisco Unified Communications Domain Manager のセルフサービスアプリケーションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-6422 2015-12-16 15:13 2015-12-11 Show GitHub Exploit DB Packet Storm
206457 4.3 警告 シスコシステムズ - Cisco Unified Email Interaction Manager and Unified Web Interaction Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-6416 2015-12-16 15:13 2015-12-10 Show GitHub Exploit DB Packet Storm
206458 4 警告 シスコシステムズ - Cisco Unified Communications Manager の Mobile and Remote Access サービスの実装における電話受信および電話設定の制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2015-6410 2015-12-16 15:13 2015-12-9 Show GitHub Exploit DB Packet Storm
206459 6.5 警告 シスコシステムズ - Cisco Videoscape Distribution Suite Service Manager におけるデータベースエントリを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-6417 2015-12-16 11:27 2015-12-10 Show GitHub Exploit DB Packet Storm
206460 7.1 危険 シスコシステムズ - Cisco Fabric Interconnect 6200 デバイス上で稼動する Unified Computing System におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-6415 2015-12-16 11:27 2015-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
451 3.1 LOW
Network
google chrome Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromi… Update CWE-119
CWE-284
Incorrect Access of Indexable Resource ('Range Error') 
Improper Access Control
CVE-2026-8545 2026-05-19 23:53 2026-05-15 Show GitHub Exploit DB Packet Storm
452 - - - A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build… New CWE-209
Information Exposure Through an Error Message
CVE-2026-7860 2026-05-19 23:50 2026-05-19 Show GitHub Exploit DB Packet Storm
453 7.3 HIGH
Local
- - A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface. New CWE-266
 Incorrect Privilege Assignment
CVE-2026-22069 2026-05-19 23:50 2026-05-19 Show GitHub Exploit DB Packet Storm
454 5.3 MEDIUM
Network
- - The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any… New CWE-284
Improper Access Control
CVE-2026-32994 2026-05-19 23:50 2026-05-19 Show GitHub Exploit DB Packet Storm
455 6.3 MEDIUM
Adjacent
- - There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface. New CWE-200
Information Exposure
CVE-2026-44408 2026-05-19 23:50 2026-05-19 Show GitHub Exploit DB Packet Storm
456 4.3 MEDIUM
Network
- - Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.… New CWE-862
 Missing Authorization
CVE-2026-45442 2026-05-19 23:50 2026-05-19 Show GitHub Exploit DB Packet Storm
457 5.3 MEDIUM
Network
google chrome Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory vi… Update CWE-125
Out-of-bounds Read
CVE-2026-8541 2026-05-19 23:47 2026-05-15 Show GitHub Exploit DB Packet Storm
458 - - - The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitr… New CWE-639
CWE-915
 Authorization Bypass Through User-Controlled Key
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-46721 2026-05-19 23:47 2026-05-19 Show GitHub Exploit DB Packet Storm
459 - - - The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP req… New CWE-611
XXE
CVE-2026-46722 2026-05-19 23:47 2026-05-19 Show GitHub Exploit DB Packet Storm
460 - - - The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data … New CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2026-46723 2026-05-19 23:47 2026-05-19 Show GitHub Exploit DB Packet Storm