Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206551 4.3 警告 アップル - Apple iOS および Safari などで使用される WebKit における重要な閲覧履歴情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-7050 2015-12-14 16:12 2015-12-8 Show GitHub Exploit DB Packet Storm
206552 2.6 注意 アップル - 複数の Apple 製品の xnu の サンドボックス機能における ASLR 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2015-7046 2015-12-14 16:12 2015-12-8 Show GitHub Exploit DB Packet Storm
206553 6.8 警告 アップル - 複数の Apple 製品の AppSandbox における Contacts へのアクセスの取り消しを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-7001 2015-12-14 16:12 2015-12-8 Show GitHub Exploit DB Packet Storm
206554 9.3 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR のシェーダーフィルタの実装における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2015-8445 2015-12-14 10:29 2015-12-8 Show GitHub Exploit DB Packet Storm
206555 10 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-8457 2015-12-14 10:03 2015-12-8 Show GitHub Exploit DB Packet Storm
206556 9.3 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2015-8456 2015-12-14 10:03 2015-12-8 Show GitHub Exploit DB Packet Storm
206557 4.3 警告 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR における ASLR 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2015-8453 2015-12-14 10:03 2015-12-8 Show GitHub Exploit DB Packet Storm
206558 9.3 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-8446 2015-12-14 10:03 2015-12-8 Show GitHub Exploit DB Packet Storm
206559 10 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-8440 2015-12-14 09:59 2015-12-8 Show GitHub Exploit DB Packet Storm
206560 9.3 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR の SharedObject オブジェクトの実装における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2015-8439 2015-12-14 09:59 2015-12-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
571 7.6 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter … Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46408 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
572 6.4 MEDIUM
Network
- - Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… Update CWE-79
Cross-site Scripting
CVE-2020-37237 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
573 6.4 MEDIUM
Network
- - CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… Update CWE-79
Cross-site Scripting
CVE-2020-37238 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
574 5.3 MEDIUM
Network
- - bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can… Update CWE-352
 Origin Validation Error
CVE-2020-37241 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
575 5.4 MEDIUM
Network
- - CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality… Update CWE-79
Cross-site Scripting
CVE-2021-47955 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
576 8.8 HIGH
Network
- - TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can… Update CWE-352
 Origin Validation Error
CVE-2021-47976 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
577 7.1 HIGH
Network
- - Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i… Update CWE-89
SQL Injection
CVE-2021-47980 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
578 5.4 MEDIUM
Network
- - Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par… Update CWE-79
Cross-site Scripting
CVE-2021-47981 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
579 7.1 HIGH
Network
- - Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Att… New CWE-89
SQL Injection
CVE-2018-25319 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
580 4.3 MEDIUM
Network
- - phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authentic… Update CWE-862
 Missing Authorization
CVE-2026-45007 2026-05-19 02:25 2026-05-16 Show GitHub Exploit DB Packet Storm