Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211381 4 警告 オラクル - Oracle Fusion Middleware の Oracle Directory Server Enterprise Edition における Admin Console に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0401 2015-01-22 12:31 2015-01-20 Show GitHub Exploit DB Packet Storm
211382 3.5 注意 オラクル - Oracle Fusion Middleware の Oracle SOA Suite における Fabric Layer に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0414 2015-01-22 12:31 2015-01-20 Show GitHub Exploit DB Packet Storm
211383 4.3 警告 オラクル - Oracle Fusion Middleware の Oracle Forms における Forms Services に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0420 2015-01-22 12:31 2015-01-20 Show GitHub Exploit DB Packet Storm
211384 4.3 警告 オラクル - Oracle Fusion Middleware の Oracle Access Manager における Integration with OAM に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0434 2015-01-22 12:31 2015-01-20 Show GitHub Exploit DB Packet Storm
211385 6 警告 オラクル - Oracle E-Business Suite の Oracle Applications DBA における DB Privileges に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0393 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
211386 4 警告 オラクル - Oracle E-Business Suite の Oracle Application Object Library における Session Management に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0415 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
211387 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Framework における Error Messages に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0404 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
211388 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Telecommunications Billing Integrator における OA Based UI for Bill Summary に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0380 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
211389 6.4 警告 オラクル - Oracle E-Business Suite の Oracle Marketing における Audience に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-6583 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
211390 5 警告 オラクル - Oracle E-Business Suite の Oracle HCM Configuration Workbench における Rapid Implementation に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-6582 2015-01-22 12:17 2015-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
931 4.2 MEDIUM
Network
- - Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_… New CWE-613
 Insufficient Session Expiration
CVE-2026-41519 2026-05-8 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
932 - - - Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial p… New CWE-20
CWE-918
 Improper Input Validation 
Server-Side Request Forgery (SSRF) 
CVE-2026-41654 2026-05-8 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
933 4.3 MEDIUM
Network
- - Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. Th… New CWE-203
 Information Exposure Through Discrepancy
CVE-2026-44263 2026-05-8 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
934 4.3 MEDIUM
Network
- - Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has… New CWE-80
Basic XSS
CVE-2026-44264 2026-05-8 00:46 2026-05-8 Show GitHub Exploit DB Packet Storm
935 7.7 HIGH
Network
- - Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the origina… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41688 2026-05-8 00:45 2026-05-8 Show GitHub Exploit DB Packet Storm
936 9.6 CRITICAL
Network
- - Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in th… Update CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-42090 2026-05-8 00:44 2026-05-5 Show GitHub Exploit DB Packet Storm
937 8.1 HIGH
Network
- - Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary… Update CWE-22
Path Traversal
CVE-2026-42075 2026-05-8 00:43 2026-05-5 Show GitHub Exploit DB Packet Storm
938 5.3 MEDIUM
Network
- - Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/… Update CWE-285
Improper Authorization
CVE-2026-41572 2026-05-8 00:43 2026-05-5 Show GitHub Exploit DB Packet Storm
939 6.5 MEDIUM
Network
- - titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscr… Update CWE-200
Information Exposure
CVE-2026-42092 2026-05-8 00:43 2026-05-5 Show GitHub Exploit DB Packet Storm
940 4.4 MEDIUM
Network
- - PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows user… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42140 2026-05-8 00:43 2026-05-5 Show GitHub Exploit DB Packet Storm