Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209221 6.8 警告 Elasticsearch - Elasticsearch のデフォルト設定における任意の MVEL 式および Java コードをを実行される脆弱性 CWE-16
環境設定
CVE-2014-3120 2015-06-26 16:11 2014-05-22 Show GitHub Exploit DB Packet Storm
209222 5 警告 Firebird Project - Firebird の xdr_status_vector 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9323 2015-06-26 16:07 2014-12-9 Show GitHub Exploit DB Packet Storm
209223 4.3 警告 Elasticsearch - Elasticsearch の CORS 機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-6439 2015-06-26 16:07 2014-10-1 Show GitHub Exploit DB Packet Storm
209224 5 警告 Node.js Foundation - Node.js におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2014-5256 2015-06-26 16:07 2014-07-31 Show GitHub Exploit DB Packet Storm
209225 7.5 危険 Elasticsearch - Elasticsearch Logstash における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-4326 2015-06-26 16:07 2014-06-24 Show GitHub Exploit DB Packet Storm
209226 4.3 警告 ntop - ntop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4165 2015-06-26 16:07 2014-06-11 Show GitHub Exploit DB Packet Storm
209227 5 警告 Gluster, Inc.
Novell
- GlusterFS の __socket_proto_state_machine 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2014-3619 2015-06-26 16:07 2014-09-9 Show GitHub Exploit DB Packet Storm
209228 7.5 危険 Google - Google Chrome で使用される Google V8 におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-6668 2015-06-26 16:07 2013-11-5 Show GitHub Exploit DB Packet Storm
209229 7.5 危険 SAP - SAP Mobile Platform における XML 外部エンティティの脆弱性 CWE-Other
その他
CVE-2015-5068 2015-06-26 10:30 2015-06-11 Show GitHub Exploit DB Packet Storm
209230 5 警告 Pearson Education, Inc. - Pearson ProctorCache がハードコードされたパスワードを使用する問題 CWE-255
CWE-Other
CVE-2015-0972 2015-06-25 17:35 2015-06-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1521 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name o… NVD-CWE-noinfo
CVE-2026-43118 2026-05-9 02:30 2026-05-6 Show GitHub Exploit DB Packet Storm
1522 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm-verity: correctly handle dm_bufio_client_create() failure If either of the calls to dm_bufio_client_create() in verity_fec_ctr… NVD-CWE-noinfo
CVE-2026-43132 2026-05-9 02:26 2026-05-6 Show GitHub Exploit DB Packet Storm
1523 7.9 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload o… NVD-CWE-noinfo
CVE-2026-43133 2026-05-9 02:25 2026-05-6 Show GitHub Exploit DB Packet Storm
1524 4.8 MEDIUM
Network
linuxcontainers incus Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database… CWE-295
Improper Certificate Validation 
CVE-2026-40243 2026-05-9 02:23 2026-05-7 Show GitHub Exploit DB Packet Storm
1525 8.2 HIGH
Network
quarkus quarkus Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec… CWE-863
 Incorrect Authorization
CVE-2026-39852 2026-05-9 02:18 2026-05-6 Show GitHub Exploit DB Packet Storm
1526 - - - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.P… CWE-79
Cross-site Scripting
CVE-2026-42794 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1527 9.8 CRITICAL
Network
- - Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRE… CWE-1392
 Use of Default Credentials
CVE-2026-42072 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1528 6.1 MEDIUM
Network
- - MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker t… CWE-80
Basic XSS
CVE-2026-42030 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1529 - - - pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, t… CWE-89
SQL Injection
CVE-2026-41889 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1530 7.8 HIGH
Local
- - PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line argu… CWE-88
CWE-93
Argument Injection
CRLF Injection
CVE-2026-41570 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm