Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
212191 4.7 警告 マイクロソフト - 複数の Microsoft Windows 製品のカーネルモードドライバの mrxdav.sys における偽装保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-0011 2015-01-15 16:05 2015-01-13 Show GitHub Exploit DB Packet Storm
212192 6.1 警告 マイクロソフト - 複数の Microsoft Windows 製品の Network Location Awareness サービスにおける意図しない許容設定を誘発される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-0006 2015-01-15 16:04 2015-01-13 Show GitHub Exploit DB Packet Storm
212193 7.2 危険 マイクロソフト - 複数の Microsoft Windows 製品の User Profile Service における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-0004 2015-01-15 16:03 2015-01-13 Show GitHub Exploit DB Packet Storm
212194 7.2 危険 マイクロソフト - 複数の Microsoft Windows 製品の Application Compatibility コンポーネントにおける権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-0002 2015-01-15 16:02 2015-01-13 Show GitHub Exploit DB Packet Storm
212195 1.9 注意 マイクロソフト - 複数の Microsoft Windows 製品の Windows Error Reporting コンポーネントにおける Protected Process Light 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-0001 2015-01-15 16:02 2015-01-13 Show GitHub Exploit DB Packet Storm
212196 7.5 危険 Yourmembers - WordPress 用 Code Futures YourMembers プラグインの includes/ym-download_functions.include.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-100003 2015-01-15 15:58 2014-10-14 Show GitHub Exploit DB Packet Storm
212197 6.8 警告 MKT Lines - WordPress 用 SEO Plugin LiveOptim プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-100001 2015-01-15 15:57 2014-04-15 Show GitHub Exploit DB Packet Storm
212198 7.5 危険 Dev4Press - WordPress 用 GD Star Rating プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2839 2015-01-15 15:57 2014-03-28 Show GitHub Exploit DB Packet Storm
212199 6.8 警告 Dev4Press - WordPress 用 GD Star Rating プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-2838 2015-01-15 15:57 2014-03-28 Show GitHub Exploit DB Packet Storm
212200 7.1 危険 Mozilla Foundation - Windows 上で稼動する Mozilla Firefox における Gecko Media Plugin サンドボックス保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-8643 2015-01-15 14:14 2014-11-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1521 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name o… NVD-CWE-noinfo
CVE-2026-43118 2026-05-9 02:30 2026-05-6 Show GitHub Exploit DB Packet Storm
1522 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm-verity: correctly handle dm_bufio_client_create() failure If either of the calls to dm_bufio_client_create() in verity_fec_ctr… NVD-CWE-noinfo
CVE-2026-43132 2026-05-9 02:26 2026-05-6 Show GitHub Exploit DB Packet Storm
1523 7.9 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload o… NVD-CWE-noinfo
CVE-2026-43133 2026-05-9 02:25 2026-05-6 Show GitHub Exploit DB Packet Storm
1524 4.8 MEDIUM
Network
linuxcontainers incus Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database… CWE-295
Improper Certificate Validation 
CVE-2026-40243 2026-05-9 02:23 2026-05-7 Show GitHub Exploit DB Packet Storm
1525 8.2 HIGH
Network
quarkus quarkus Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec… CWE-863
 Incorrect Authorization
CVE-2026-39852 2026-05-9 02:18 2026-05-6 Show GitHub Exploit DB Packet Storm
1526 - - - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.P… CWE-79
Cross-site Scripting
CVE-2026-42794 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1527 9.8 CRITICAL
Network
- - Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRE… CWE-1392
 Use of Default Credentials
CVE-2026-42072 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1528 6.1 MEDIUM
Network
- - MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker t… CWE-80
Basic XSS
CVE-2026-42030 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1529 - - - pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, t… CWE-89
SQL Injection
CVE-2026-41889 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm
1530 7.8 HIGH
Local
- - PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line argu… CWE-88
CWE-93
Argument Injection
CRLF Injection
CVE-2026-41570 2026-05-9 02:16 2026-05-9 Show GitHub Exploit DB Packet Storm