Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206841 5.8 警告 Apache Software Foundation
PayPal
- 複数の製品で使用される Apache Axis における SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5784 2016-02-16 17:26 2012-11-4 Show GitHub Exploit DB Packet Storm
206842 4.3 警告
Network
KDDI - HOME SPOT CUBE における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2016-1141 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206843 4.3 警告
Network
KDDI - HOME SPOT CUBE におけるクリックジャッキングの脆弱性 CWE-Other
その他
CVE-2016-1140 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206844 5 警告 Squid-cache.org - Squid の cachemgr.cgi におけるサービス運用妨害 (メモリ消費) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-5643 2016-02-16 17:23 2012-12-17 Show GitHub Exploit DB Packet Storm
206845 4.3 警告
Network
KDDI - HOME SPOT CUBE におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-1139 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206846 4.7 警告
Network
KDDI - HOME SPOT CUBE における HTTP ヘッダインジェクションの脆弱性 CWE-Other
その他
CVE-2016-1138 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206847 4.7 警告
Network
KDDI - HOME SPOT CUBE におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2016-1137 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206848 4.3 警告
Network
KDDI - HOME SPOT CUBE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1136 2016-02-16 17:23 2016-01-27 Show GitHub Exploit DB Packet Storm
206849 4.3 警告 Mozilla Foundation - 複数の Mozilla 製品におけるクロスサイトスクリプティングの脆弱性 CWE-16
環境設定
CVE-2012-4209 2016-02-16 17:21 2012-11-20 Show GitHub Exploit DB Packet Storm
206850 4.3 警告 Mozilla Foundation - 複数の Mozilla 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4207 2016-02-16 17:21 2012-11-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2631 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… CWE-77
Command Injection
CVE-2026-38702 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
2632 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… CWE-77
Command Injection
CVE-2026-38703 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
2633 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ve… CWE-77
Command Injection
CVE-2026-38707 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
2634 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlie… CWE-77
Command Injection
CVE-2026-38704 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
2635 8.6 HIGH
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st… CWE-193
 Off-by-one Error
CVE-2026-49127 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2636 5.3 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF by… CWE-93
CRLF Injection
CVE-2026-49130 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2637 5.8 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allow… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-49129 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2638 4.1 MEDIUM
Network
- - A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endp… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10052 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
2639 2.7 LOW
Network
- - A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL que… CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-10078 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
2640 7.7 HIGH
Network
- - A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice tha… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42965 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm