Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207751 7.5 危険 Novell
The Document Foundation
- LibreOffice の Impress Remote のソケットマネージャにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-3693 2015-06-22 17:23 2014-11-5 Show GitHub Exploit DB Packet Storm
207752 4.3 警告 サン・マイクロシステムズ
Apache Software Foundation
- Apache OpenOffice および OpenOffice.org の OLE プレビュー生成におけるドキュメントに任意のデータを埋め込まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3575 2015-06-22 17:23 2014-08-21 Show GitHub Exploit DB Packet Storm
207753 10 危険 Novell
The Document Foundation
Canonical
- LibreOffice における脆弱性 CWE-noinfo
情報不足
CVE-2014-0247 2015-06-22 17:21 2014-06-23 Show GitHub Exploit DB Packet Storm
207754 4.3 警告 Igor Sysoev - nginx の SMTP proxy の mail/ngx_mail_smtp_handler.c の STARTTLS 実装における暗号化された SMTP セッションにコマンドを挿入される脆弱性 CWE-Other
その他
CVE-2014-3556 2015-06-22 16:30 2014-08-5 Show GitHub Exploit DB Packet Storm
207755 - - サムスン - ** 削除 ** Samsung Galaxy S にプリインストールされた Swiftkey が言語パックのアップデートを正しく検証しない脆弱性 - CVE-2015-2865 2015-06-22 16:30 2015-06-16 Show GitHub Exploit DB Packet Storm
207756 6.8 警告 Vesta Control Panel - Vesta Control Panel にクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-2861 2015-06-22 16:23 2015-06-16 Show GitHub Exploit DB Packet Storm
207757 4 警告 シスコシステムズ - Cisco IOS XR におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-4195 2015-06-22 15:24 2015-06-18 Show GitHub Exploit DB Packet Storm
207758 5 警告 シスコシステムズ - Cisco WebEx Meeting Center の Web ベースの管理インターフェースにおけるアカウント名を列挙される脆弱性 CWE-200
情報漏えい
CVE-2015-4194 2015-06-22 15:24 2015-06-18 Show GitHub Exploit DB Packet Storm
207759 5 警告 シスコシステムズ - Cisco IOS XR におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-4191 2015-06-22 15:24 2015-06-17 Show GitHub Exploit DB Packet Storm
207760 6.8 警告 Labsmedia Cloud Computing Center - ClickHeat におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-4659 2015-06-22 14:42 2015-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 9.8 CRITICAL
Network
- - Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell comma… New CWE-78
OS Command 
CVE-2026-42076 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
72 7.1 HIGH
Network
- - Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can … New CWE-94
Code Injection
CVE-2026-40563 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
73 - - - wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog. New - CVE-2026-38669 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
74 - - - An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. New - CVE-2026-37461 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
75 8.8 HIGH
Network
- - NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or con… New CWE-183
 Permissive List of Allowed Inputs
CVE-2026-29514 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
76 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and … New CWE-693
 Protection Mechanism Failure
CVE-2026-26956 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
77 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0. New CWE-94
CWE-693
Code Injection
 Protection Mechanism Failure
CVE-2026-26332 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
78 9.6 CRITICAL
Adjacent
- - Buffer overflow due to incorrect authorization in PLC FW New CWE-863
 Incorrect Authorization
CVE-2026-25293 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
79 5.5 MEDIUM
Local
- - Memory corruption while processing IOCTL command when device is in power-save state. New CWE-749
 Exposed Dangerous Method or Function
CVE-2026-25266 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
80 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can es… New CWE-94
CWE-693
Code Injection
 Protection Mechanism Failure
CVE-2026-24781 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm