Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207301 10 危険 Sierra Wireless - ALEOS を使用する Sierra Wireless の複数のデバイスがハードコードされたパスワードを使用する問題 CWE-200
CWE-Other
CVE-2015-2897 2015-08-17 15:25 2015-08-7 Show GitHub Exploit DB Packet Storm
207302 9.3 危険 マイクロソフト - Microsoft Internet Explorer 7 から 11 および Microsoft Edge における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2441 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207303 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 から 11 および Microsoft Edge における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2442 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207304 9.3 危険 マイクロソフト - Microsoft Internet Explorer 10 および 11 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2443 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207305 9.3 危険 マイクロソフト - Microsoft Internet Explorer 7 から 11 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2452 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207306 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 から 11 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2451 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207307 4.3 警告 マイクロソフト - Microsoft Internet Explorer 7 から 11 および Microsoft Edge における ASLR 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2015-2449 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207308 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 から 11 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2444 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207309 4.3 警告 マイクロソフト - Microsoft Internet Explorer 10 における ASLR 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2015-2445 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
207310 9.3 危険 マイクロソフト - Microsoft Internet Explorer 11 および Microsoft Edge における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2015-2446 2015-08-17 15:09 2015-08-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 - - - A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON p… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-7541 2026-05-9 00:49 2026-05-8 Show GitHub Exploit DB Packet Storm
212 - - - A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusi… New CWE-436
CWE-918
 Interpretation Conflict
Server-Side Request Forgery (SSRF) 
CVE-2026-8034 2026-05-9 00:49 2026-05-8 Show GitHub Exploit DB Packet Storm
213 - - - A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/… New CWE-79
Cross-site Scripting
CVE-2026-8106 2026-05-9 00:49 2026-05-8 Show GitHub Exploit DB Packet Storm
214 8.1 HIGH
Network
- - DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands… New CWE-78
OS Command 
CVE-2022-50994 2026-05-9 00:48 2026-05-8 Show GitHub Exploit DB Packet Storm
215 5.3 MEDIUM
Network
- - Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can access … New CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-41928 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
216 6.1 MEDIUM
Network
- - Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulati… New CWE-79
Cross-site Scripting
CVE-2026-41929 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
217 8.6 HIGH
Network
- - The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to per… New CWE-89
SQL Injection
CVE-2026-4935 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
218 7.5 HIGH
Network
- - Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network. New CWE-138
 Improper Neutralization of Special Elements
CVE-2026-26129 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
219 7.5 HIGH
Network
- - Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. New CWE-74
Injection
CVE-2026-26164 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm
220 8.8 HIGH
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. New CWE-79
Cross-site Scripting
CVE-2026-32207 2026-05-9 00:47 2026-05-8 Show GitHub Exploit DB Packet Storm