Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207361 6.8 警告 dhcpcd project - Android などの製品で使用される dhcpcd の dhcp.c の get_option 関数における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-7912 2015-07-31 14:33 2014-11-15 Show GitHub Exploit DB Packet Storm
207362 2.1 注意 Python Software Foundation - pip におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-8991 2015-07-31 11:07 2014-11-12 Show GitHub Exploit DB Packet Storm
207363 6.4 警告 thekelleys - Dnsmasq の tcp_request 関数におけるプロセスのメモリを読み取られる脆弱性 CWE-Other
その他
CVE-2015-3294 2015-07-31 10:35 2015-04-10 Show GitHub Exploit DB Packet Storm
207364 3.5 注意 OpenStack - OpenStack Dashboard におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3988 2015-07-31 10:33 2015-05-1 Show GitHub Exploit DB Packet Storm
207365 5 警告 The PHP Group
アップル
- PHP の Fileinfo コンポーネントで使用される readelf.c ファイル内の donote 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3710 2015-07-30 16:40 2014-10-17 Show GitHub Exploit DB Packet Storm
207366 5 警告 The Tcpdump Group - tcpdump の geonet_print 関数における整数アンダーフローの脆弱性 CWE-189
数値処理の問題
CVE-2014-8768 2015-07-30 16:37 2014-11-12 Show GitHub Exploit DB Packet Storm
207367 7.5 危険 Novell
Mercurial
- Mercurial の sshpeer の _validaterepo 関数における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-9462 2015-07-30 16:29 2014-12-29 Show GitHub Exploit DB Packet Storm
207368 7.5 危険 X.Org Foundation
Debian
Canonical
- X.Org X11 および libX11 の include/X11/Xlibint.h の MakeBigReq および SetReqLen マクロにおける脆弱性 CWE-189
数値処理の問題
CVE-2013-7439 2015-07-30 16:27 2013-03-9 Show GitHub Exploit DB Packet Storm
207369 7.5 危険 The PHP Group
file project
- PHP の Fileinfo コンポーネントで使用される file の readelf.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-9653 2015-07-30 16:20 2014-12-17 Show GitHub Exploit DB Packet Storm
207370 7.5 危険 The Tcpdump Group - tcpdump の IPv6 モビリティプリンタの mobility_opt_print 関数における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2015-0261 2015-07-30 16:18 2015-03-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
21 5.4 MEDIUM
Network
- - A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to … New CWE-79
Cross-site Scripting
CVE-2026-36388 2026-05-8 03:45 2026-05-8 Show GitHub Exploit DB Packet Storm
22 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Drain commands in target_reset handler tcm_loop_target_reset() violates the SCSI EH contract: it returns … Update CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2026-43054 2026-05-8 03:28 2026-05-2 Show GitHub Exploit DB Packet Storm
23 4.7 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivation When inactivating an inode with node-format extended attributes, xfs_attr3_n… Update CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-43053 2026-05-8 03:24 2026-05-2 Show GitHub Exploit DB Packet Storm
24 7.0 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL an… Update CWE-416
 Use After Free
CVE-2026-43050 2026-05-8 03:21 2026-05-2 Show GitHub Exploit DB Packet Storm
25 7.1 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check tdls flag in ieee80211_tdls_oper When NL80211_TDLS_ENABLE_LINK is called, the code only checks if the stati… Update NVD-CWE-noinfo
CVE-2026-43052 2026-05-8 03:19 2026-05-2 Show GitHub Exploit DB Packet Storm
26 - - - In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clone bio completes Stale rq->bio values have been observed to cause double-initia… New - CVE-2026-43278 2026-05-8 03:16 2026-05-6 Show GitHub Exploit DB Packet Storm
27 8.1 HIGH
Adjacent
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports with… Update CWE-125
Out-of-bounds Read
CVE-2026-43051 2026-05-8 03:00 2026-05-2 Show GitHub Exploit DB Packet Storm
28 9.8 CRITICAL
Network
paloaltonetworks pan-os A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code w… New CWE-787
 Out-of-bounds Write
CVE-2026-0300 2026-05-8 02:46 2026-05-7 Show GitHub Exploit DB Packet Storm
29 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit after resize When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lin… Update CWE-125
Out-of-bounds Read
CVE-2026-31742 2026-05-8 02:42 2026-05-2 Show GitHub Exploit DB Packet Storm
30 9.1 CRITICAL
Network
torproject tor Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. New CWE-684
 Incorrect Provision of Specified Functionality
CVE-2026-44597 2026-05-8 02:34 2026-05-7 Show GitHub Exploit DB Packet Storm