Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
210521 4.3 警告 Mozilla Foundation - Mozilla Firefox および SeaMonkey の Chrome Object Wrapper の実装における DOM オブジェクト制限を回避される脆弱性 CWE-Other
その他
CVE-2014-8631 2014-12-12 15:11 2014-12-2 Show GitHub Exploit DB Packet Storm
210522 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-1594 2014-12-12 15:11 2014-12-2 Show GitHub Exploit DB Packet Storm
210523 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品の mozilla::FileBlockCache::Read 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-1593 2014-12-12 15:10 2014-12-2 Show GitHub Exploit DB Packet Storm
210524 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品の xul.dll の nsHtml5TreeOperation 関数における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-1592 2014-12-12 15:10 2014-12-2 Show GitHub Exploit DB Packet Storm
210525 4.3 警告 Mozilla Foundation - Mozilla Firefox および SeaMonkey における重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2014-1591 2014-12-12 15:09 2014-12-2 Show GitHub Exploit DB Packet Storm
210526 4.3 警告 Mozilla Foundation - 複数の Mozilla 製品の XMLHttpRequest.prototype.send メソッドにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-1590 2014-12-12 15:09 2014-12-2 Show GitHub Exploit DB Packet Storm
210527 6.8 警告 Mozilla Foundation - Mozilla Firefox および SeaMonkey におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2014-1589 2014-12-12 15:09 2014-12-2 Show GitHub Exploit DB Packet Storm
210528 6.8 警告 Mozilla Foundation - Mozilla Firefox および SeaMonkey のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-1588 2014-12-12 15:08 2014-12-2 Show GitHub Exploit DB Packet Storm
210529 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-1587 2014-12-12 15:08 2014-12-2 Show GitHub Exploit DB Packet Storm
210530 3.5 注意 マイクロソフト - Microsoft Exchange Server の Outlook Web App におけるユーザを任意の Web サイトにリダイレクトされる脆弱性 CWE-20
不適切な入力確認
CVE-2014-6336 2014-12-12 11:19 2014-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 18, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
181 6.8 MEDIUM
Network
- - ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arb… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40500 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
182 9.4 CRITICAL
Network
- - Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered o… New CWE-200
CWE-215
Information Exposure
 Insertion of Sensitive Information Into Debugging Code
CVE-2026-40173 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
183 7.8 HIGH
Local
- - Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she… New CWE-20
CWE-78
 Improper Input Validation 
OS Command 
CVE-2026-40176 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
184 6.1 MEDIUM
Network
- - ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasse… New CWE-79
Cross-site Scripting
CVE-2026-40186 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
185 8.8 HIGH
Network
- - Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source… New CWE-20
CWE-78
 Improper Input Validation 
OS Command 
CVE-2026-40261 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
186 9.1 CRITICAL
Network
- - A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace bound… New CWE-1220
 Insufficient Granularity of Access Control
CVE-2026-6388 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
187 - - - Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attac… New CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-40192 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
188 2.9 LOW
Local
- - Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path. New CWE-426
 Untrusted Search Path
CVE-2026-40947 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
189 5.4 MEDIUM
Network
- - Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields… New CWE-185
CWE-863
 Incorrect Regular Expression
 Incorrect Authorization
CVE-2026-39350 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
190 - - - Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of… New CWE-79
Cross-site Scripting
CVE-2026-40179 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm