Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207791 4.3 警告 シトリックス・システムズ - Citrix NetScaler Service Delivery Appliance SVM デバイスの NetScaler ADC および NetScaler Gateway におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-7997 2015-11-19 17:57 2015-11-11 Show GitHub Exploit DB Packet Storm
207792 5 警告 シトリックス・システムズ - Citrix NetScaler Service Delivery Appliance SVM デバイスの NetScaler ADC および NetScaler Gateway における資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-7996 2015-11-19 17:57 2015-11-11 Show GitHub Exploit DB Packet Storm
207793 4.6 警告 Canonical - Ubuntu lxd パッケージの lxd-unix.socket systemd ユニットファイルにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-8222 2015-11-19 14:59 2015-11-12 Show GitHub Exploit DB Packet Storm
207794 10 危険 Google - Google Picasa における整数オーバーフローの脆弱性 CWE-119
CWE-189
CVE-2015-8221 2015-11-19 14:59 2015-10-29 Show GitHub Exploit DB Packet Storm
207795 7.5 危険 SolarWinds - SolarWinds DameWare Mini Remote Control の DWRCC.exe の URI ハンドラにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-8220 2015-11-19 14:59 2015-11-10 Show GitHub Exploit DB Packet Storm
207796 7.2 危険 Todd C. Miller - Sudo の sudoedit における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5602 2015-11-19 14:42 2015-11-1 Show GitHub Exploit DB Packet Storm
207797 2.1 注意 DELL EMC (旧 EMC Corporation) - EMC VPLEX GeoSynchrony のデフォルト設定における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-6847 2015-11-19 14:04 2015-11-17 Show GitHub Exploit DB Packet Storm
207798 2.6 注意 MAYO project - Drupal 用 MAYO テーマにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8233 2015-11-19 13:43 2015-11-11 Show GitHub Exploit DB Packet Storm
207799 4.3 警告 UC Profile project - Drupal 用 UC Profile モジュールにおける匿名のユーザプロファイルから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-8232 2015-11-19 13:43 2015-11-10 Show GitHub Exploit DB Packet Storm
207800 6.8 警告 シスコシステムズ - Cisco FireSIGHT Management Center のルール更新機能における SSL サーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2015-6357 2015-11-19 13:42 2015-11-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2511 6.1 MEDIUM
Network
- - Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Ma… CWE-352
 Origin Validation Error
CVE-2026-22880 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
2512 8.0 HIGH
Network
- - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an… CWE-22
Path Traversal
CVE-2026-4858 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
2513 8.4 HIGH
Network
- - Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent mac… CWE-77
Command Injection
CVE-2026-2740 2026-05-22 00:26 2026-05-21 Show GitHub Exploit DB Packet Storm
2514 7.1 HIGH
Network
- - Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. Thi… CWE-359
CWE-522
 Exposure of Private Personal Information to an Unauthorized Actor
 Insufficiently Protected Credentials
CVE-2025-13477 2026-05-22 00:24 2026-05-21 Show GitHub Exploit DB Packet Storm
2515 7.5 HIGH
Network
- - Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: throug… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-13479 2026-05-22 00:24 2026-05-21 Show GitHub Exploit DB Packet Storm
2516 5.7 MEDIUM
Network
- - Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 b… CWE-613
 Insufficient Session Expiration
CVE-2026-1815 2026-05-22 00:24 2026-05-22 Show GitHub Exploit DB Packet Storm
2517 6.3 MEDIUM
Network
- - Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Appli… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-1816 2026-05-22 00:24 2026-05-22 Show GitHub Exploit DB Packet Storm
2518 5.3 MEDIUM
Network
isc bind An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sendin… CWE-606
 Unchecked Input for Loop Condition
CVE-2026-5950 2026-05-22 00:24 2026-05-20 Show GitHub Exploit DB Packet Storm
2519 5.9 MEDIUM
Network
isc bind Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. … CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2026-5947 2026-05-22 00:24 2026-05-20 Show GitHub Exploit DB Packet Storm
2520 9.8 CRITICAL
Network
isc bind A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BI… CWE-416
 Use After Free
CVE-2026-3593 2026-05-22 00:24 2026-05-20 Show GitHub Exploit DB Packet Storm