Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
208101 4 警告 PHP工房 - 「【Gallery01】PC、スマホ、ガラケー3デバイス対応写真ギャラリーCMS フリー(無料)版」におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2982 2015-08-26 17:38 2015-08-12 Show GitHub Exploit DB Packet Storm
208102 2.6 注意 PHP工房 - 「【Gallery01】PC、スマホ、ガラケー3デバイス対応写真ギャラリーCMS フリー(無料)版」におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-2983 2015-08-26 17:28 2015-08-12 Show GitHub Exploit DB Packet Storm
208103 3.5 注意 DELL EMC (旧 EMC Corporation) - EMC Documentum D2 の Lockbox における管理者のチケットを復号される脆弱性 CWE-200
情報漏えい
CVE-2015-4537 2015-08-26 16:44 2015-08-20 Show GitHub Exploit DB Packet Storm
208104 5 警告 シスコシステムズ - Cisco Wireless LAN Controller デバイスのソフトウェア上で稼動する Internet Access Point Protocol モジュールにおける不正なトラフィック転送を誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2015-6258 2015-08-26 16:24 2015-08-21 Show GitHub Exploit DB Packet Storm
208105 5 警告 シスコシステムズ - Cisco ASR 5000 デバイスのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-6256 2015-08-26 16:24 2015-08-20 Show GitHub Exploit DB Packet Storm
208106 3.5 注意 シスコシステムズ - Cisco Prime Infrastructure におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-4331 2015-08-26 16:24 2015-08-20 Show GitHub Exploit DB Packet Storm
208107 6.8 警告 Actiontec Electronics, Inc. - Actiontec GT784WN モデムのファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-2905 2015-08-26 16:20 2015-08-11 Show GitHub Exploit DB Packet Storm
208108 8.3 危険 Actiontec Electronics, Inc. - Actiontec GT784WN モデムのファームウェアにおける root アクセス権を取得される脆弱性 CWE-Other
その他
CVE-2015-2904 2015-08-26 16:10 2015-08-11 Show GitHub Exploit DB Packet Storm
208109 6 警告 ヒューレット・パッカード - 複数の HP CentralView 製品における重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2015-5408 2015-08-26 15:51 2015-08-12 Show GitHub Exploit DB Packet Storm
208110 6 警告 ヒューレット・パッカード - 複数の HP CentralView 製品における重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2015-5407 2015-08-26 15:51 2015-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1661 - - - Reserved. Details will be published at disclosure. - CVE-2026-45393 2026-05-12 23:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1662 7.5 HIGH
Network
- - A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. - CVE-2026-4890 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1663 5.3 MEDIUM
Network
- - A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. - CVE-2026-4891 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1664 8.4 HIGH
Local
- - A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet. - CVE-2026-4892 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1665 5.3 MEDIUM
Network
- - An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information. - CVE-2026-4893 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1666 - - - An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing le… CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2026-35227 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1667 - - - A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unau… CWE-306
Missing Authentication for Critical Function
CVE-2026-5029 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
1668 - - - ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's br… CWE-79
Cross-site Scripting
CVE-2026-6909 2026-05-12 23:15 2026-05-11 Show GitHub Exploit DB Packet Storm
1669 - - - ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's br… CWE-79
Cross-site Scripting
CVE-2026-6956 2026-05-12 23:15 2026-05-11 Show GitHub Exploit DB Packet Storm
1670 9.8 CRITICAL
Network
cross-crypto cross-implementation CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused b… CWE-121
CWE-122
Stack-based Buffer Overflow
Heap-based Buffer Overflow
CVE-2026-41509 2026-05-12 23:15 2026-05-8 Show GitHub Exploit DB Packet Storm