Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206611 6.8 警告 FFmpeg - FFmpeg の libavcodec/ivi.c の ff_ivi_init_planes 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2015-8364 2015-11-30 11:34 2015-11-14 Show GitHub Exploit DB Packet Storm
206612 6.8 警告 FFmpeg - FFmpeg の libavcodec/jpeg2000dec.c の jpeg2000_read_main_headers 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2015-8363 2015-11-30 11:34 2015-11-14 Show GitHub Exploit DB Packet Storm
206613 8.5 危険 DELL EMC (旧 EMC Corporation) - EMC Isilon OneFS における root 権限を取得される脆弱性 CWE-Other
その他
CVE-2015-6848 2015-11-30 11:12 2015-11-24 Show GitHub Exploit DB Packet Storm
206614 7.2 危険 ヒューレット・パッカード - HP LoadRunner の Virtual Table Server における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2015-6857 2015-11-30 11:06 2015-11-24 Show GitHub Exploit DB Packet Storm
206615 5 警告 シスコシステムズ - Cisco ASR 5000 デバイスのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-6382 2015-11-30 11:00 2015-11-25 Show GitHub Exploit DB Packet Storm
206616 1.9 注意 Linux - Linux Kernel の fs/fhandle.c の handle_to_path 関数におけるサイズ制限を回避される脆弱性 CWE-362
競合状態
CVE-2015-1420 2015-11-27 16:37 2015-01-30 Show GitHub Exploit DB Packet Storm
206617 4.3 警告 Apache Software Foundation - Apache Cordova におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5256 2015-11-27 12:04 2015-11-27 Show GitHub Exploit DB Packet Storm
206618 4.3 警告 CSL DualCom - CSL DualCom GPRS CS2300-R デバイスのファームウェアにおける設定を変更される脆弱性 CWE-Other
その他
CVE-2015-7288 2015-11-26 15:51 2015-11-23 Show GitHub Exploit DB Packet Storm
206619 7.5 危険 CSL DualCom - CSL DualCom GPRS CS2300-R デバイスのファームウェアにおける任意のコマンドを実行される脆弱性 CWE-255
証明書・パスワード管理
CVE-2015-7287 2015-11-26 15:51 2015-11-23 Show GitHub Exploit DB Packet Storm
206620 6.4 警告 CSL DualCom - CSL DualCom GPRS CS2300-R デバイスのファームウェアにおける暗号保護メカニズムを破られる脆弱性 CWE-310
CWE-Other
CVE-2015-7286 2015-11-26 15:51 2015-11-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 3.1 LOW
Network
- - Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation v… New CWE-20
 Improper Input Validation 
CVE-2026-8536 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
412 3.6 LOW
Local
- - Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-lik… New CWE-78
CWE-88
OS Command 
Argument Injection
CVE-2026-46483 2026-05-16 00:16 2026-05-16 Show GitHub Exploit DB Packet Storm
413 4.3 MEDIUM
Network
- - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate… New CWE-863
 Incorrect Authorization
CVE-2026-45148 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
414 7.5 HIGH
Network
- - libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciou… New CWE-190
 Integer Overflow or Wraparound
CVE-2026-44673 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
415 - - - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.… New CWE-79
CWE-94
CWE-1188
Cross-site Scripting
Code Injection
 Insecure Default Initialization of Resource
CVE-2026-44670 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
416 - - - HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its … New CWE-78
OS Command 
CVE-2026-44666 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
417 - - - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decode… New CWE-79
CWE-116
CWE-1188
Cross-site Scripting
 Improper Encoding or Escaping of Output
 Insecure Default Initialization of Resource
CVE-2026-44588 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
418 10.0 CRITICAL
Network
- - Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secr… New CWE-326
CWE-345
Inadequate Encryption Strength
 Insufficient Verification of Data Authenticity
CVE-2026-44523 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
419 - - - The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an ope… New CWE-601
Open Redirect
CVE-2026-44427 2026-05-16 00:16 2026-05-15 Show GitHub Exploit DB Packet Storm
420 6.5 MEDIUM
Network
vllm vllm vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect sh… Update CWE-131
CWE-704
Incorrect Calculation of Buffer Size
 Incorrect Type Conversion or Cast
CVE-2026-44223 2026-05-16 00:16 2026-05-13 Show GitHub Exploit DB Packet Storm