Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
213171 5 警告 ClamAV
Fedora Project
- ClamAV におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2015-1463 2015-02-13 14:18 2015-01-27 Show GitHub Exploit DB Packet Storm
213172 7.5 危険 Comodo - COMODO Backup の bdisk.sys ドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9633 2015-02-13 14:15 2014-10-8 Show GitHub Exploit DB Packet Storm
213173 7.8 危険 アルバネットワークス株式会社 - Aruba Instant のファームウェアにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-1348 2015-02-13 14:15 2015-01-27 Show GitHub Exploit DB Packet Storm
213174 4.3 警告 LANDesk - LANDESK Management Suite の管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5360 2015-02-13 14:15 2014-08-19 Show GitHub Exploit DB Packet Storm
213175 7.1 危険 Pexip - Pexip Infinity における Management および Conferencing Node になりすまされる脆弱性 CWE-Other
その他
CVE-2014-8779 2015-02-13 14:15 2014-11-13 Show GitHub Exploit DB Packet Storm
213176 7.1 危険 ブルーコートシステムズ - Blue Coat ProxyClient および Unified Agent における ProxySG Client Managers を偽装される脆弱性 CWE-310
暗号の問題
CVE-2015-1454 2015-02-13 14:15 2015-01-23 Show GitHub Exploit DB Packet Storm
213177 5 警告 Privoxy Developers - Privoxy の pcrs.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-1381 2015-02-13 14:15 2015-01-24 Show GitHub Exploit DB Packet Storm
213178 4.3 警告 snipsnap - SnipSnap におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9559 2015-02-13 14:15 2015-01-31 Show GitHub Exploit DB Packet Storm
213179 5 警告 Privoxy Developers - Privoxy の parsers.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-1382 2015-02-13 14:15 2015-01-24 Show GitHub Exploit DB Packet Storm
213180 2.1 注意 Puppet - puppetlabs-rabbitmq における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-9568 2015-02-13 14:15 2015-01-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2011 - - - Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal I… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-43897 2026-05-14 03:27 2026-05-12 Show GitHub Exploit DB Packet Storm
2012 8.2 HIGH
Network
- - exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per lin… CWE-88
Argument Injection
CVE-2026-43893 2026-05-14 03:27 2026-05-12 Show GitHub Exploit DB Packet Storm
2013 - - - pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:… CWE-125
CWE-191
Out-of-bounds Read
 Integer Underflow (Wrap or Wraparound)
CVE-2026-43916 2026-05-14 03:27 2026-05-12 Show GitHub Exploit DB Packet Storm
2014 9.1 CRITICAL
Network
- - sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's… CWE-200
CWE-522
Information Exposure
 Insufficiently Protected Credentials
CVE-2026-45091 2026-05-14 03:27 2026-05-12 Show GitHub Exploit DB Packet Storm
2015 - - - MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-R… CWE-22
Path Traversal
CVE-2026-42600 2026-05-14 03:26 2026-05-12 Show GitHub Exploit DB Packet Storm
2016 - - - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) logi… CWE-362
Race Condition
CVE-2026-43930 2026-05-14 03:26 2026-05-12 Show GitHub Exploit DB Packet Storm
2017 8.8 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th… CWE-89
CWE-841
SQL Injection
 Improper Enforcement of Behavioral Workflow
CVE-2026-43937 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
2018 8.1 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43938 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
2019 7.3 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43939 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
2020 6.5 MEDIUM
Network
- - requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addr… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42175 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm