Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
207891 4.9 警告 オラクル - Oracle Sun Solaris における UNIX filesystem に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4770 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207892 5 警告 オラクル - Oracle Sun Systems Products Suite の Oracle VM Server for SPARC における LDOM Manager に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4750 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207893 1.9 注意 オラクル - Oracle Sun Solaris における DHCP Server に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2662 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207894 3.8 注意 オラクル - Oracle Sun Solaris における Kernel Zones virtualized NIC driver に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2651 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207895 7.2 危険 オラクル - Oracle Sun Solaris における rmformat Utility に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2631 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207896 4.9 警告 オラクル - Oracle Sun Solaris Cluster における DevFS に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2616 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207897 4.9 警告 オラクル - Oracle Sun Solaris における NVM Express SSD driver に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2614 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207898 4.9 警告 オラクル - Oracle Sun Solaris における CPU performance counters drivers に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2609 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207899 4.9 警告 オラクル - Oracle Sun Solaris における S10 Branded Zone に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2589 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
207900 1.9 注意 オラクル - Oracle Sun Solaris における NFSv4 に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2580 2015-07-21 17:15 2015-07-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1111 8.6 HIGH
Network
- - Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to… CWE-121
Stack-based Buffer Overflow
CVE-2026-42469 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1112 6.1 MEDIUM
Network
- - Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-suppli… CWE-79
Cross-site Scripting
CVE-2025-69606 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1113 6.5 MEDIUM
Network
- - A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request. CWE-77
Command Injection
CVE-2026-26461 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1114 7.5 HIGH
Network
- - An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) … CWE-787
 Out-of-bounds Write
CVE-2026-37457 2026-05-8 00:15 2026-05-2 Show GitHub Exploit DB Packet Storm
1115 6.5 MEDIUM
Network
- - goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the C… CWE-352
 Origin Validation Error
CVE-2026-42091 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1116 - - - Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/fi… CWE-79
Cross-site Scripting
CVE-2026-42138 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1117 - - - Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41686 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1118 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/a… CWE-200
CWE-312
Information Exposure
 Cleartext Storage of Sensitive Information
CVE-2026-42151 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1119 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a… CWE-400
CWE-789
 Uncontrolled Resource Consumption
 Memory Allocation with Excessive Size Value
CVE-2026-42154 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm
1120 3.7 LOW
Network
- - Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number. CWE-193
 Off-by-one Error
CVE-2026-43964 2026-05-8 00:15 2026-05-5 Show GitHub Exploit DB Packet Storm