Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207611 6.8 警告 ヒューレット・パッカード - HP ArcSight SmartConnectors におけるデバイスを偽装される脆弱性 CWE-310
CWE-Other
CVE-2015-2902 2015-11-5 16:10 2015-11-3 Show GitHub Exploit DB Packet Storm
207612 6.8 警告 MiniUPnP Project - MiniUPnP クライアントの igd_desc_parse.c の IGDstartelt 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-6031 2015-11-5 15:39 2015-09-15 Show GitHub Exploit DB Packet Storm
207613 6.8 警告 Oxwall - Oxwall におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-5534 2015-11-5 15:12 2015-09-8 Show GitHub Exploit DB Packet Storm
207614 4.3 警告 シスコシステムズ - Cisco SocialMiner の WeChat ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-6356 2015-11-5 14:57 2015-11-3 Show GitHub Exploit DB Packet Storm
207615 5 警告 シスコシステムズ - ブレードサーバ上で稼働する Cisco Unified Computing System の Web インターフェースにおける重要なバージョン情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-6355 2015-11-5 14:57 2015-11-2 Show GitHub Exploit DB Packet Storm
207616 7.2 危険 IBM - Linux および AIX 上で稼動する IBM Tivoli Storage Manager の Tivoli Monitoring における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-4927 2015-11-5 14:45 2015-10-27 Show GitHub Exploit DB Packet Storm
207617 5.5 警告 IBM - IBM InfoSphere Information Server におけるジョブの実行制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5021 2015-11-5 14:45 2015-10-27 Show GitHub Exploit DB Packet Storm
207618 7.8 危険 PowerDNS - PowerDNS Recursor および Authoritative Server のラベル展開機能におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-5470 2015-11-5 14:28 2015-04-23 Show GitHub Exploit DB Packet Storm
207619 5.8 警告 Apache Software Foundation - Apache Ambari におけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2015-5210 2015-11-5 13:56 2015-10-13 Show GitHub Exploit DB Packet Storm
207620 6.5 警告 Apache Software Foundation - Apache Ambari における管理者権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-3270 2015-11-5 13:56 2015-10-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1931 - - - MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-R… CWE-22
Path Traversal
CVE-2026-42600 2026-05-14 03:26 2026-05-12 Show GitHub Exploit DB Packet Storm
1932 - - - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) logi… CWE-362
Race Condition
CVE-2026-43930 2026-05-14 03:26 2026-05-12 Show GitHub Exploit DB Packet Storm
1933 8.8 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th… CWE-89
CWE-841
SQL Injection
 Improper Enforcement of Behavioral Workflow
CVE-2026-43937 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1934 8.1 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43938 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1935 7.3 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43939 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1936 6.5 MEDIUM
Network
- - requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addr… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42175 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1937 - - - DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw strin… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42300 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1938 - - - Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affect… CWE-288
CWE-306
CWE-841
Authentication Bypass Using an Alternate Path or Channel
Missing Authentication for Critical Function
 Improper Enforcement of Behavioral Workflow
CVE-2026-42303 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1939 4.3 MEDIUM
Network
- - Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes… CWE-862
 Missing Authorization
CVE-2026-42541 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1940 8.8 HIGH
Network
- - AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed i… CWE-79
CWE-94
CWE-1188
Cross-site Scripting
Code Injection
 Insecure Default Initialization of Resource
CVE-2026-43892 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm