Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
213891 5 警告 Pivotal Software, Inc. - RabbitMQ の management プラグインにおける CRLF インジェクションの脆弱性 CWE-Other
その他
CVE-2014-9650 2015-01-28 16:27 2014-10-29 Show GitHub Exploit DB Packet Storm
213892 4.3 警告 Pivotal Software, Inc. - RabbitMQ の management プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9649 2015-01-28 16:16 2014-10-29 Show GitHub Exploit DB Packet Storm
213893 7.5 危険 CatBot project - CatBot の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-1367 2015-01-28 16:02 2015-01-15 Show GitHub Exploit DB Packet Storm
213894 4.3 警告 Pixabay - WordPress 用 Pixabay Images プラグインの pixabay-images.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-1366 2015-01-28 16:01 2015-01-14 Show GitHub Exploit DB Packet Storm
213895 5 警告 Pixabay - WordPress 用 Pixabay Images プラグインの pixabay-images.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2015-1365 2015-01-28 16:00 2015-01-14 Show GitHub Exploit DB Packet Storm
213896 6.8 警告 Google - Google Chrome で使用される Blink の platform/image-decoders/ImageFrame.h におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2015-1361 2015-01-28 15:59 2015-01-21 Show GitHub Exploit DB Packet Storm
213897 7.5 危険 Google - Google Chrome で使用される Skia におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2015-1360 2015-01-28 15:58 2015-01-21 Show GitHub Exploit DB Packet Storm
213898 6.8 警告 Google - Google Chrome で使用される PDFium の fpdfapi/fpdf_font/font_int.h におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2015-1359 2015-01-28 15:57 2015-01-21 Show GitHub Exploit DB Packet Storm
213899 4.3 警告 Google - Android 上で稼働する Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9648 2015-01-28 15:56 2014-01-3 Show GitHub Exploit DB Packet Storm
213900 6.8 警告 Google - Google Chrome で使用される PDFium におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9647 2015-01-28 15:55 2014-09-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2901 7.5 HIGH
Network
h2o h2o A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi… CWE-200
CWE-284
NVD-CWE-noinfo
Information Exposure
Improper Access Control
CVE-2026-8750 2026-05-20 03:22 2026-05-17 Show GitHub Exploit DB Packet Storm
2902 6.5 MEDIUM
Network
- - Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in t… CWE-863
 Incorrect Authorization
CVE-2026-42883 2026-05-20 03:19 2026-05-12 Show GitHub Exploit DB Packet Storm
2903 6.2 MEDIUM
Network
- - LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/featur… CWE-79
Cross-site Scripting
CVE-2026-42045 2026-05-20 03:19 2026-05-13 Show GitHub Exploit DB Packet Storm
2904 9.8 CRITICAL
Network
mozilla firefox Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. CWE-693
 Protection Mechanism Failure
CVE-2026-8401 2026-05-20 03:16 2026-05-13 Show GitHub Exploit DB Packet Storm
2905 5.3 MEDIUM
Network
mozilla firefox Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. CWE-20
CWE-79
CWE-119
 Improper Input Validation 
Cross-site Scripting
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-8391 2026-05-20 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
2906 6.5 MEDIUM
Network
mozilla firefox Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-8388 2026-05-20 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
2907 6.5 MEDIUM
Network
- - LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before … CWE-522
 Insufficiently Protected Credentials
CVE-2026-8368 2026-05-20 03:16 2026-05-13 Show GitHub Exploit DB Packet Storm
2908 - - - Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system CWE-502
 Deserialization of Untrusted Data
CVE-2026-6009 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm
2909 8.7 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-suppl… CWE-79
CWE-434
CWE-646
Cross-site Scripting
 Unrestricted Upload of File with Dangerous Type 
 Reliance on File Name or Extension of Externally-Supplied File
CVE-2026-45315 2026-05-20 03:16 2026-05-16 Show GitHub Exploit DB Packet Storm
2910 9.8 CRITICAL
Network
- - An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based … CWE-22
CWE-287
Path Traversal
Improper Authentication
CVE-2026-36829 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm