Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
214071 4 警告 オラクル - Oracle Siebel CRM の Siebel Core EAI における Integration Business Services に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0363 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214072 3.5 注意 オラクル - Oracle Siebel CRM の Siebel Core - EAI における Integration Business Services に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0364 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214073 4.3 警告 オラクル - Oracle Siebel CRM の Siebel Core - Server Infrastructure における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0365 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214074 5 警告 オラクル - Oracle Siebel CRM の Siebel Core - EAI における Java Integration に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0366 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214075 4.3 警告 オラクル - Oracle Siebel CRM の Siebel UI Framework における AX/HI Web UI に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0369 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214076 3.5 注意 オラクル - Oracle Siebel CRM の Siebel Public Sector における Public Sector Portal に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0384 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214077 4 警告 オラクル - Oracle Siebel CRM の Siebel Core - Server OM Services における Security - LDAP Security Adapter に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0387 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214078 4 警告 オラクル - Oracle Siebel CRM の Siebel UI Framework における Portal Framework に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0388 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214079 4.6 警告 オラクル - Oracle Siebel CRM の Siebel Core - Server BizLogic Script における Config - Scripting に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0392 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
214080 4 警告 オラクル - Oracle Siebel CRM の Siebel Life Sciences における Clinical Trip Report に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0398 2015-01-22 10:48 2015-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2861 6.5 MEDIUM
Network
- - LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before … CWE-522
 Insufficiently Protected Credentials
CVE-2026-8368 2026-05-20 03:16 2026-05-13 Show GitHub Exploit DB Packet Storm
2862 - - - Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system CWE-502
 Deserialization of Untrusted Data
CVE-2026-6009 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm
2863 8.7 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-suppl… CWE-79
CWE-434
CWE-646
Cross-site Scripting
 Unrestricted Upload of File with Dangerous Type 
 Reliance on File Name or Extension of Externally-Supplied File
CVE-2026-45315 2026-05-20 03:16 2026-05-16 Show GitHub Exploit DB Packet Storm
2864 9.8 CRITICAL
Network
- - An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based … CWE-22
CWE-287
Path Traversal
Improper Authentication
CVE-2026-36829 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm
2865 5.9 MEDIUM
Network
- - NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the br… CWE-476
 NULL Pointer Dereference
CVE-2026-32134 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm
2866 - - - In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and S… - CVE-2025-61081 2026-05-20 03:16 2026-05-20 Show GitHub Exploit DB Packet Storm
2867 9.8 CRITICAL
Network
- - The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerabi… CWE-78
OS Command 
CVE-2026-31226 2026-05-20 03:14 2026-05-13 Show GitHub Exploit DB Packet Storm
2868 8.8 HIGH
Local
microsoft 365_apps
office
office_long_term_servicing_channel
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. CWE-1220
 Insufficient Granularity of Access Control
CVE-2026-35436 2026-05-20 03:05 2026-05-13 Show GitHub Exploit DB Packet Storm
2869 5.5 MEDIUM
Local
microsoft 365_apps
office
office_long_term_servicing_channel
word
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. CWE-552
 Files or Directories Accessible to External Parties
CVE-2026-35440 2026-05-20 03:05 2026-05-13 Show GitHub Exploit DB Packet Storm
2870 8.4 HIGH
Local
microsoft 365_apps
office
office_long_term_servicing_channel
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-416
 Use After Free
CVE-2026-40358 2026-05-20 03:05 2026-05-13 Show GitHub Exploit DB Packet Storm