Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
208881 6.5 警告 X.Org Foundation - X.Org Server における整数オーバーフローの脆弱性 CWE-Other
その他
CVE-2014-8094 2015-06-4 16:52 2014-12-9 Show GitHub Exploit DB Packet Storm
208882 4.3 警告 Apache Software Foundation - Apache Sling の Sling API コンポーネントおよび Servlets Post コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2944 2015-06-4 15:38 2015-05-27 Show GitHub Exploit DB Packet Storm
208883 4 警告 Palo Alto Networks - PAN-OS の管理インターフェースにおける XML 外部エンティティの脆弱性 CWE-Other
その他
CVE-2015-4162 2015-06-4 15:10 2015-05-29 Show GitHub Exploit DB Packet Storm
208884 5.8 警告 Thycotic - iOS 用 Thycotic Password Manager Secret Server アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2015-4094 2015-06-4 14:37 2015-05-26 Show GitHub Exploit DB Packet Storm
208885 7.5 危険 SAP - SAP Afaria における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-4161 2015-06-4 14:09 2015-05-21 Show GitHub Exploit DB Packet Storm
208886 5 警告 SAP - SAP コンテンツサーバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2015-4157 2015-06-4 14:09 2015-05-21 Show GitHub Exploit DB Packet Storm
208887 7.5 危険 SAP - SAP ASE Database Platform における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-4160 2015-06-4 14:09 2015-05-21 Show GitHub Exploit DB Packet Storm
208888 5 警告 SAP - SAP Netweaver Application Server ABAP および SAP Netweaver Application Server Java におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2015-4158 2015-06-4 14:09 2015-05-21 Show GitHub Exploit DB Packet Storm
208889 5 警告 SAP - 複数の SAP 製品の LZH 解凍の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2015-2278 2015-06-4 14:09 2015-05-12 Show GitHub Exploit DB Packet Storm
208890 7.5 危険 SAP - SAP HANA Web-based Development Workbench における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-4159 2015-06-4 14:09 2015-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1351 7.8 HIGH
Local
qualcomm fastconnect_6200_firmware
fastconnect_6900_firmware
fastconnect_7800_firmware
iqx5121_firmware
iqx7181_firmware
qca0000_firmware
sc8380xp_firmware
sd865_5g_firmware
sm6250_fir…
Memory corruption when another driver calls an IOCTL with invalid input/output buffer. CWE-822
CWE-119
 Untrusted Pointer Dereference
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2025-47408 2026-05-7 03:03 2026-05-5 Show GitHub Exploit DB Packet Storm
1352 5.5 MEDIUM
Local
qualcomm cologne_firmware
fastconnect_6700_firmware
fastconnect_6900_firmware
fastconnect_7800_firmware
iqx5121_firmware
iqx7181_firmware
qca0000_firmware
qcm5430_firmware
qcm6490_firm…
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. CWE-126
CWE-125
 Buffer Over-read
Out-of-bounds Read
CVE-2025-47406 2026-05-7 03:02 2026-05-5 Show GitHub Exploit DB Packet Storm
1353 7.0 HIGH
Local
qualcomm cq7790_firmware
cq8725s_firmware
fastconnect_6200_firmware
fastconnect_6700_firmware
fastconnect_6900_firmware
fastconnect_7800_firmware
g2_gen_1_firmware
molokai_firmware
net…
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2025-47407 2026-05-7 03:02 2026-05-5 Show GitHub Exploit DB Packet Storm
1354 7.8 HIGH
Local
qualcomm qxm1096_firmware
robotics_rb2_firmware
robotics_rb5_firmware
sa4150p_firmware
sa4155p_firmware
sa6145p_firmware
sa6150p_firmware
sa6155p_firmware
sa7255p_firmware
sa7775p_f…
Memory Corruption when copying data from a freed source while executing performance counter deselect operation. CWE-416
 Use After Free
CVE-2026-24082 2026-05-7 03:02 2026-05-5 Show GitHub Exploit DB Packet Storm
1355 7.8 HIGH
Local
qualcomm cologne_firmware
fastconnect_6900_firmware
fastconnect_7800_firmware
sc8380xp_firmware
snapdragon_ar1_gen_1_firmware
wcd9378c_firmware
wcd9380_firmware
wcd9385_firmware
wcn786…
Memory corruption while processing IOCTL command when device is in power-save state. CWE-749
CWE-787
 Exposed Dangerous Method or Function
 Out-of-bounds Write
CVE-2026-25266 2026-05-7 03:02 2026-05-5 Show GitHub Exploit DB Packet Storm
1356 9.8 CRITICAL
Network
qualcomm qca7005_firmware Buffer overflow due to incorrect authorization in PLC FW CWE-863
 Incorrect Authorization
CVE-2026-25293 2026-05-7 03:01 2026-05-5 Show GitHub Exploit DB Packet Storm
1357 9.1 CRITICAL
Network
apache opennlp XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor … CWE-611
XXE
CVE-2026-40682 2026-05-7 03:00 2026-05-5 Show GitHub Exploit DB Packet Storm
1358 9.8 CRITICAL
Network
apache opennlp Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(C… CWE-470
Unsafe Reflection
CVE-2026-42027 2026-05-7 03:00 2026-05-5 Show GitHub Exploit DB Packet Storm
1359 9.8 CRITICAL
Network
nginxui nginx_ui Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/insta… CWE-284
CWE-306
Improper Access Control
Missing Authentication for Critical Function
CVE-2026-42222 2026-05-7 02:47 2026-05-5 Show GitHub Exploit DB Packet Storm
1360 7.2 HIGH
Network
dlink di-8100_firmware A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The atta… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-7851 2026-05-7 02:40 2026-05-6 Show GitHub Exploit DB Packet Storm