Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 10:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206931 6.8 警告 オラクル - Oracle E-Business Suite の Oracle iSupplier Portal における XML input に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4851 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206932 6.8 警告 オラクル - Oracle E-Business Suite の Oracle Payments における Punch-in に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4849 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206933 3.6 注意 オラクル - Oracle E-Business Suite の Oracle Applications Manager における SQL Extensions に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4846 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206934 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Application Object Library における Java APIs - AOL/J に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4845 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206935 4 警告 オラクル - Oracle E-Business Suite の Oracle Applications DBA における Online patching に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4762 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206936 3.6 注意 オラクル - Oracle Enterprise Manager Grid Control の Enterprise Manager Ops Center における Ops Center に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2633 2015-10-22 14:53 2015-10-20 Show GitHub Exploit DB Packet Storm
206937 1.2 注意 オラクル - Oracle Hyperion の Hyperion Installation Technology における Essbase Rapid Deploy に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4823 2015-10-22 14:50 2015-10-20 Show GitHub Exploit DB Packet Storm
206938 7.5 危険 Mozilla Foundation
オラクル
- Mozilla Network Security Services におけるデータスマグリング攻撃を実行される脆弱性 CWE-Other
その他
CVE-2014-1569 2015-10-22 14:20 2014-12-1 Show GitHub Exploit DB Packet Storm
206939 5.1 警告 オラクル
SpringSource
- SpringSource Spring Framework における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-1622 2015-10-22 14:20 2010-06-17 Show GitHub Exploit DB Packet Storm
206940 3.5 注意 オラクル - Oracle Fusion Middleware の Oracle HTTP Server における Web Listener に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4914 2015-10-22 14:17 2015-10-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
691 3.0 LOW
Local
- - ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard container image inherits the default root user because the Dockerfile lacks a USER… New CWE-269
 Improper Privilege Management
CVE-2026-44218 2026-05-14 02:02 2026-05-13 Show GitHub Exploit DB Packet Storm
692 3.7 LOW
Network
- - ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyzer/sca/osv.py and src/ciguard/analyzer/sca/endoflife.py) call payload = json.lo… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44219 2026-05-14 02:02 2026-05-13 Show GitHub Exploit DB Packet Storm
693 3.2 LOW
Local
- - ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function in src/ciguard/discovery.py walks a directory tree following symlinks, with cycl… New CWE-59
Link Following
CVE-2026-44220 2026-05-14 02:02 2026-05-13 Show GitHub Exploit DB Packet Storm
694 4.4 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during mo… Update CWE-20
CWE-158
 Improper Input Validation 
 Improper Neutralization of Null Byte or NUL Character
CVE-2026-43895 2026-05-14 02:02 2026-05-12 Show GitHub Exploit DB Packet Storm
695 5.3 MEDIUM
Network
- - protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded … New CWE-176
 Improper Handling of Unicode Encoding
CVE-2026-44288 2026-05-14 02:01 2026-05-14 Show GitHub Exploit DB Packet Storm
696 8.7 HIGH
Network
- - protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When ge… New CWE-94
Code Injection
CVE-2026-44295 2026-05-14 02:01 2026-05-14 Show GitHub Exploit DB Packet Storm
697 5.5 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.… Update CWE-190
 Integer Overflow or Wraparound
CVE-2026-43894 2026-05-14 02:01 2026-05-12 Show GitHub Exploit DB Packet Storm
698 5.5 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator … Update CWE-190
CWE-787
 Integer Overflow or Wraparound
 Out-of-bounds Write
CVE-2026-41257 2026-05-14 02:01 2026-05-12 Show GitHub Exploit DB Packet Storm
699 5.5 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter fil… Update CWE-158
 Improper Neutralization of Null Byte or NUL Character
CVE-2026-41256 2026-05-14 02:00 2026-05-12 Show GitHub Exploit DB Packet Storm
700 8.4 HIGH
Local
- - JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument… Update CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-43990 2026-05-14 02:00 2026-05-13 Show GitHub Exploit DB Packet Storm