Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206611 7.8 危険 ZTE - ZTE ZXHN H108N R1A デバイスの cgi-bin/webproc における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2015-7250 2016-01-5 16:34 2015-11-3 Show GitHub Exploit DB Packet Storm
206612 6.8 警告 ZTE - ZTE ZXHN H108N R1A デバイスにおけるアクセス制限を回避される脆弱性 CWE-264
CWE-Other
CVE-2015-7249 2016-01-5 16:34 2015-11-3 Show GitHub Exploit DB Packet Storm
206613 5 警告 ZTE - ZTE ZXHN H108N R1A デバイスにおけるユーザ名およびパスワードハッシュを取得される脆弱性 CWE-200
情報漏えい
CVE-2015-7248 2016-01-5 16:34 2015-11-3 Show GitHub Exploit DB Packet Storm
206614 5 警告 Amped Wireless - Amped Wireless R10000 デバイスのファームウェアにおけるレスポンスを偽装される脆弱性 CWE-Other
その他
CVE-2015-7279 2016-01-5 15:26 2015-12-10 Show GitHub Exploit DB Packet Storm
206615 6.8 警告 Amped Wireless - Amped Wireless R10000 デバイスのファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-7278 2016-01-5 15:26 2015-12-10 Show GitHub Exploit DB Packet Storm
206616 9.3 危険 Amped Wireless - Amped Wireless R10000 デバイスのファームウェアの Web 管理インターフェースにおける管理者権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2015-7277 2016-01-5 15:26 2015-12-10 Show GitHub Exploit DB Packet Storm
206617 6.8 警告 Pacom - Pacom 1000 CCU および RTU GMS デバイスにおけるコントローラとベース間のデータストリームを偽造される脆弱性 CWE-310
暗号の問題
CVE-2014-3260 2016-01-5 15:18 2014-05-7 Show GitHub Exploit DB Packet Storm
206618 5 警告 IDERA, Inc. - Idera Uptime Infrastructure Monitor の up.time クライアントにおけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2015-2894 2016-01-5 15:07 2015-12-3 Show GitHub Exploit DB Packet Storm
206619 7.5 危険 IDERA, Inc. - Idera Uptime Infrastructure Monitor の up.time クライアントにおけるバッファオーバーフローの脆弱性 CWE-119
CWE-Other
CVE-2015-2895 2016-01-5 15:07 2015-12-3 Show GitHub Exploit DB Packet Storm
206620 5 警告 IDERA, Inc. - Idera Uptime Infrastructure Monitor の up.time クライアントにおけるバージョンなどの重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-2896 2016-01-5 15:07 2015-12-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1071 4.3 MEDIUM
Network
- - Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo… CWE-352
 Origin Validation Error
CVE-2018-25337 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1072 7.5 HIGH
Network
siemens teamcenter A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All … CWE-798
 Use of Hard-coded Credentials
CVE-2026-33893 2026-05-19 02:26 2026-05-12 Show GitHub Exploit DB Packet Storm
1073 5.4 MEDIUM
Network
- - Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is proce… CWE-79
Cross-site Scripting
CVE-2026-23695 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1074 4.3 MEDIUM
Network
- - CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG file… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2021-47958 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1075 8.8 HIGH
Network
- - Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager… CWE-94
Code Injection
CVE-2021-47964 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1076 7.5 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-ad… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-44826 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1077 - - - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3. CWE-79
Cross-site Scripting
CVE-2026-45616 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1078 8.1 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator t… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46407 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1079 7.6 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46408 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1080 6.4 MEDIUM
Network
- - Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… CWE-79
Cross-site Scripting
CVE-2020-37237 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm