Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
208421 7.8 危険 unzoo - unzoo におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-1846 2015-05-21 14:21 2015-03-31 Show GitHub Exploit DB Packet Storm
208422 10 危険 unzoo - unzoo の EntrReadArch 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-1845 2015-05-21 14:21 2015-03-31 Show GitHub Exploit DB Packet Storm
208423 3.6 注意 レッドハット - Red Hat Enterprise Linux の kexec-tools パッケージで配布される kexec-tools 用 Red Hat module-setup.sh スクリプトにおける任意のファイルに書き込まれる脆弱性 CWE-Other
その他
CVE-2015-0267 2015-05-21 14:11 2015-05-12 Show GitHub Exploit DB Packet Storm
208424 2.6 注意 大垣共立銀行 - Android 版 スマホ通帳における情報管理不備の脆弱性 CWE-255
証明書・パスワード管理
CVE-2015-0875 2015-05-21 10:04 2015-02-13 Show GitHub Exploit DB Packet Storm
208425 4.3 警告 Debian
Samba Project
- Paul's PPP Package の plugins/radius/util.c の rc_mksid 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-3310 2015-05-20 17:49 2015-04-14 Show GitHub Exploit DB Packet Storm
208426 4.3 警告 Digium - Asterisk Open Source および Certified Asterisk における任意の SSL サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2015-3008 2015-05-20 17:49 2015-03-4 Show GitHub Exploit DB Packet Storm
208427 10 危険 ホスピーラ - Hospira Lifecare PCA 輸液ポンプにおける root 権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-3459 2015-05-20 17:46 2015-04-27 Show GitHub Exploit DB Packet Storm
208428 4 警告 OpenStack - OpenStack Image Registry and Delivery Service におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-1881 2015-05-20 17:35 2015-02-19 Show GitHub Exploit DB Packet Storm
208429 4 警告 OpenStack - OpenStack Image Registry and Delivery Service におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2014-9684 2015-05-20 17:34 2014-12-19 Show GitHub Exploit DB Packet Storm
208430 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2015-1250 2015-05-20 17:33 2015-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
691 4.4 MEDIUM
Local
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, res… CWE-124
CWE-191
Buffer Underflow
 Integer Underflow (Wrap or Wraparound)
CVE-2026-26204 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
692 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security… CWE-307
CWE-362
CWE-367
mproper Restriction of Excessive Authentication Attempts
Race Condition
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-26206 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
693 6.5 MEDIUM
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() i… CWE-121
CWE-400
Stack-based Buffer Overflow
 Uncontrolled Resource Consumption
CVE-2026-28221 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
694 9.0 CRITICAL
Network
- - Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchroniz… CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-30893 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
695 9.8 CRITICAL
Network
- - Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send… CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25316 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
696 9.8 CRITICAL
Network
- - Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se… CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25317 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
697 9.8 CRITICAL
Network
- - Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca… CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25318 2026-05-1 00:11 2026-04-30 Show GitHub Exploit DB Packet Storm
698 7.4 HIGH
Network
- - Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects … CWE-125
Out-of-bounds Read
CVE-2026-42799 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
699 7.4 HIGH
Network
- - NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/s… CWE-476
 NULL Pointer Dereference
CVE-2026-42800 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm
700 6.5 MEDIUM
Network
- - Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.… CWE-200
CWE-359
Information Exposure
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-7382 2026-05-1 00:09 2026-04-30 Show GitHub Exploit DB Packet Storm