Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207391 10 危険 アップル
日立
サン・マイクロシステムズ
オラクル
- Oracle Java SE の Java Runtime Environment における JMX の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0450 2015-08-11 18:21 2013-02-1 Show GitHub Exploit DB Packet Storm
207392 7.5 危険 OpenJPEG project - OpenJPEG におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-6045 2015-08-11 17:04 2013-12-3 Show GitHub Exploit DB Packet Storm
207393 4.3 警告 Alexander Barton - ngIRCd の conn.c の Conn_StartLogin および cb_Read_Resolver_Result 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-5580 2015-08-11 16:58 2013-08-23 Show GitHub Exploit DB Packet Storm
207394 4.6 警告 IBM
オラクル
- Oracle Java SE における Deployment に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5888 2015-08-11 16:52 2014-01-14 Show GitHub Exploit DB Packet Storm
207395 3.7 注意 Linux - Linux Kernel の fs/nfs/write.c 内の nfs_can_extend_write 関数における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2014-2038 2015-08-11 16:52 2014-02-13 Show GitHub Exploit DB Packet Storm
207396 4.9 警告 Linux - Linux Kernel の net/packet/af_packet.c の packet_recvmsg 関数における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2013-7270 2015-08-11 16:52 2013-12-8 Show GitHub Exploit DB Packet Storm
207397 4.9 警告 Linux - Linux Kernel の drivers/isdn/mISDN/socket.c の mISDN_sock_recvmsg 関数における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2013-7266 2015-08-11 16:52 2013-12-8 Show GitHub Exploit DB Packet Storm
207398 4.3 警告 GNOME Project - GNOME libsvg における任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2013-1881 2015-08-11 16:52 2013-05-13 Show GitHub Exploit DB Packet Storm
207399 6.9 警告 Linux - Linux Kernel の drivers/usb/class/cdc-wdm.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1860 2015-08-11 16:52 2013-03-20 Show GitHub Exploit DB Packet Storm
207400 7.5 危険 アップル
Florian Frank
- JSON gem におけるサービス運用妨害 (リソース消費) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-0269 2015-08-11 16:52 2013-02-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221 9.8 CRITICAL
Network
- - ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on… New CWE-94
Code Injection
CVE-2026-38431 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
222 6.1 MEDIUM
Network
- - ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript co… New CWE-79
Cross-site Scripting
CVE-2026-38432 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
223 - - - Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1… New CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-31835 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
224 - - - Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink followin… New CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-31893 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
225 - - - SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided que… New CWE-89
SQL Injection
CVE-2026-33324 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
226 - - - Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing … New CWE-862
 Missing Authorization
CVE-2026-33420 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
227 - - - PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when t… New CWE-502
CWE-918
 Deserialization of Untrusted Data
Server-Side Request Forgery (SSRF) 
CVE-2026-34084 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
228 - - - PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 through 5.6.0, the HT… New CWE-79
Cross-site Scripting
CVE-2026-35453 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
229 8.8 HIGH
Network
- - A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server b… New CWE-94
Code Injection
CVE-2026-7841 2026-05-8 00:15 2026-05-6 Show GitHub Exploit DB Packet Storm
230 7.5 HIGH
Network
- - Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered a… New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-34473 2026-05-8 00:15 2026-05-7 Show GitHub Exploit DB Packet Storm