Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211861 10 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS の Guest Login Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5503 2014-10-9 18:19 2014-09-15 Show GitHub Exploit DB Packet Storm
211862 9 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS における任意のコマンドを挿入される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-5502 2014-10-9 18:18 2014-09-15 Show GitHub Exploit DB Packet Storm
211863 9.3 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS の診断サービスにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-5501 2014-10-9 18:18 2014-09-15 Show GitHub Exploit DB Packet Storm
211864 7.5 危険 PhpCompta - PHPCompta/NOALYSS の backup.php における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-6389 2014-10-9 17:54 2014-10-1 Show GitHub Exploit DB Packet Storm
211865 6.8 警告 Charles Cazabon - getmail の IMAP-over-SSL の実装において IMAP サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7273 2014-10-9 17:48 2014-10-7 Show GitHub Exploit DB Packet Storm
211866 7.5 危険 アルバネットワークス株式会社 - Aruba コントローラ上で稼動する ArubaOS の管理インタフェースにおける認証を回避される脆弱性 CWE-noinfo
情報不足
CVE-2014-7299 2014-10-9 17:44 2014-10-7 Show GitHub Exploit DB Packet Storm
211867 4.3 警告 Debian - apt-cacher-ng の job.cc におけるクロスサイトスクリプティングの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-4510 2014-10-9 17:38 2014-06-21 Show GitHub Exploit DB Packet Storm
211868 3.5 注意 MediaWiki - MediaWiki の Special:Preferences および Special:UserLogin のページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7295 2014-10-9 17:29 2014-09-11 Show GitHub Exploit DB Packet Storm
211869 3.6 注意 David Golden - Perl 用 Capture::Tiny モジュールにおける任意のファイルに書き込まれる脆弱性 CWE-59
リンク解釈の問題
CVE-2014-1875 2014-10-9 16:51 2014-02-6 Show GitHub Exploit DB Packet Storm
211870 7.5 危険 Google - Google Chrome で使用される Google V8 におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-7967 2014-10-9 16:19 2014-10-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 7.8 HIGH
Local
oracle application_development_framework Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. E… New CWE-284
Improper Access Control
CVE-2026-35243 2026-04-25 01:43 2026-04-22 Show GitHub Exploit DB Packet Storm
212 9.1 CRITICAL
Network
oracle enterprise_manager_base_platform Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily explo… New CWE-306
Missing Authentication for Critical Function
CVE-2026-34279 2026-04-25 01:43 2026-04-22 Show GitHub Exploit DB Packet Storm
213 6.0 MEDIUM
Local
oracle graalvm
jdk
jre
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u481 and 8u481-b50; … New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-22003 2026-04-25 01:42 2026-04-22 Show GitHub Exploit DB Packet Storm
214 9.6 CRITICAL
Network
google chrome Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.… New CWE-416
 Use After Free
CVE-2026-6919 2026-04-25 01:39 2026-04-24 Show GitHub Exploit DB Packet Storm
215 9.6 CRITICAL
Network
google chrome Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted … New CWE-125
Out-of-bounds Read
CVE-2026-6920 2026-04-25 01:39 2026-04-24 Show GitHub Exploit DB Packet Storm
216 8.3 HIGH
Network
google chrome Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) New CWE-362
Race Condition
CVE-2026-6921 2026-04-25 01:39 2026-04-24 Show GitHub Exploit DB Packet Storm
217 8.8 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javas… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-41269 2026-04-25 01:39 2026-04-24 Show GitHub Exploit DB Packet Storm
218 8.3 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Func… New CWE-284
CWE-918
Improper Access Control
Server-Side Request Forgery (SSRF) 
CVE-2026-41270 2026-04-25 01:38 2026-04-24 Show GitHub Exploit DB Packet Storm
219 8.3 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain co… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41271 2026-04-25 01:37 2026-04-24 Show GitHub Exploit DB Packet Storm
220 7.1 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Sid… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41272 2026-04-25 01:37 2026-04-24 Show GitHub Exploit DB Packet Storm