Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
215061 4.3 警告 CloudBees - CloudBees Jenkins におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2065 2014-10-23 17:32 2014-02-8 Show GitHub Exploit DB Packet Storm
215062 5 警告 CloudBees - CloudBees Jenkins の hudson/security/HudsonPrivateSecurityRealm.java におけるユーザが存在するかどうかを確認される脆弱性 CWE-200
情報漏えい
CVE-2014-2064 2014-10-23 17:32 2014-02-8 Show GitHub Exploit DB Packet Storm
215063 7.5 危険 CloudBees - CloudBees Jenkins におけるクリックジャッキング攻撃を実行される脆弱性 CWE-noinfo
情報不足
CVE-2014-2063 2014-10-23 17:32 2014-02-12 Show GitHub Exploit DB Packet Storm
215064 6.5 警告 CloudBees - CloudBees Jenkins におけるアクセスを保持される脆弱性 CWE-287
不適切な認証
CVE-2014-2062 2014-10-23 17:31 2014-02-8 Show GitHub Exploit DB Packet Storm
215065 5 警告 CloudBees - CloudBees Jenkins の PasswordParameterDefinition の入力制御におけるパスワードを取得される脆弱性 CWE-310
暗号の問題
CVE-2014-2061 2014-10-23 17:31 2014-02-8 Show GitHub Exploit DB Packet Storm
215066 7.5 危険 CloudBees - CloudBees Jenkins の Winstone サーブレットコンテナにおけるセッションをハイジャックされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2060 2014-10-23 17:31 2014-02-15 Show GitHub Exploit DB Packet Storm
215067 6.5 警告 CloudBees - CloudBees Jenkins の BuildTrigger におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2058 2014-10-23 17:30 2014-02-11 Show GitHub Exploit DB Packet Storm
215068 4 警告 CloudBees - CloudBees Jenkins における制限されているプロジェクト以外のプロジェクトを構築される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7330 2014-10-23 17:30 2013-02-14 Show GitHub Exploit DB Packet Storm
215069 4.3 警告 C97net - C97net Cart Engine の skins/default/outline.tpl におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8307 2014-10-23 16:58 2014-08-21 Show GitHub Exploit DB Packet Storm
215070 7.5 危険 C97net - C97net Cart Engine の cart.php 内の sql_query 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-8306 2014-10-23 16:58 2014-08-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1221 6.5 MEDIUM
Network
apache cloudstack The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plug… Update CWE-863
 Incorrect Authorization
CVE-2025-66170 2026-05-12 00:24 2026-05-8 Show GitHub Exploit DB Packet Storm
1222 7.5 HIGH
Network
osrg gobgp GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending… Update CWE-476
 NULL Pointer Dereference
CVE-2026-42285 2026-05-12 00:22 2026-05-7 Show GitHub Exploit DB Packet Storm
1223 5.4 MEDIUM
Network
misp misp Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-si… Update CWE-79
Cross-site Scripting
CVE-2026-8080 2026-05-12 00:21 2026-05-7 Show GitHub Exploit DB Packet Storm
1224 8.0 HIGH
Network
phoenixcontact fl_mguard_2102_firmware
fl_mguard_2105_firmware
fl_mguard_4102_pci_firmware
fl_mguard_4102_pcie_firmware
fl_mguard_4302_firmware
fl_mguard_4305_firmware
fl_mguard_centerport_firmwar…
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. Update CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2024-43384 2026-05-12 00:20 2026-05-7 Show GitHub Exploit DB Packet Storm
1225 9.8 CRITICAL
Network
mozilla firefox
thunderbird
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.… Update NVD-CWE-noinfo
CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-8091 2026-05-12 00:20 2026-05-7 Show GitHub Exploit DB Packet Storm
1226 8.1 HIGH
Network
mozilla firefox
thunderbird
Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have… Update CWE-125
CWE-416
CWE-787
Out-of-bounds Read
 Use After Free
 Out-of-bounds Write
CVE-2026-8092 2026-05-12 00:16 2026-05-7 Show GitHub Exploit DB Packet Storm
1227 7.5 HIGH
Network
google android In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Update NVD-CWE-noinfo
CVE-2025-71251 2026-05-12 00:13 2026-05-6 Show GitHub Exploit DB Packet Storm
1228 7.5 HIGH
Network
google android In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Update NVD-CWE-noinfo
CVE-2025-71252 2026-05-12 00:13 2026-05-6 Show GitHub Exploit DB Packet Storm
1229 8.1 HIGH
Network
mozilla firefox
thunderbird
Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitr… Update CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-8093 2026-05-12 00:12 2026-05-7 Show GitHub Exploit DB Packet Storm
1230 9.8 CRITICAL
Network
mozilla firefox
thunderbird
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. Update CWE-94
Code Injection
CVE-2026-8094 2026-05-12 00:12 2026-05-7 Show GitHub Exploit DB Packet Storm