Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220111 4.6 警告 オラクル - Oracle Sun Solaris 10 および 11 における Kernel/DTrace Framework の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0407 2013-11-8 11:42 2013-01-15 Show GitHub Exploit DB Packet Storm
220112 4.3 警告 オラクル - Oracle Sun Solaris 10 における Kernel/IPsec の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0406 2013-11-8 11:41 2013-04-16 Show GitHub Exploit DB Packet Storm
220113 6.4 警告 オラクル - Oracle Sun Solaris 8、9、10、および 11 における NFS クライアントマウントおよび IPv6 の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0405 2013-11-8 11:40 2013-04-16 Show GitHub Exploit DB Packet Storm
220114 3.7 注意 オラクル - Oracle Sun Solaris 10 における Kernel/Boot の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0404 2013-11-8 11:39 2013-04-16 Show GitHub Exploit DB Packet Storm
220115 1.9 注意 オラクル - Oracle Sun Solaris 8、9、10、および 11 における Utility の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0403 2013-11-8 11:38 2013-04-16 Show GitHub Exploit DB Packet Storm
220116 6.6 警告 オラクル - Oracle Sun Solaris 9 および 10 における Filesystem/cachefs の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0400 2013-11-8 11:35 2013-01-15 Show GitHub Exploit DB Packet Storm
220117 6.6 警告 オラクル - Oracle Sun Solaris 9 および 10 における Utility/Umount の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0399 2013-11-8 11:34 2013-01-15 Show GitHub Exploit DB Packet Storm
220118 5 警告 オラクル - Oracle Enterprise Manager Grid Control の APM における Business Transaction Management の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0396 2013-11-8 11:32 2013-01-15 Show GitHub Exploit DB Packet Storm
220119 4 警告 オラクル - Oracle PeopleSoft Products の PeopleSoft PeopleTools における Security の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0395 2013-11-8 11:31 2013-01-15 Show GitHub Exploit DB Packet Storm
220120 5 警告 オラクル - Oracle PeopleSoft Products の PeopleSoft HRMS における Candidate Gateway の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-0394 2013-11-8 11:30 2013-01-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
691 7.2 HIGH
Network
apache neethi Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a poli… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42404 2026-05-2 03:06 2026-05-1 Show GitHub Exploit DB Packet Storm
692 9.8 CRITICAL
Network
apache mina The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inc… CWE-502
 Deserialization of Untrusted Data
CVE-2026-42778 2026-05-2 02:55 2026-05-1 Show GitHub Exploit DB Packet Storm
693 9.8 CRITICAL
Network
apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, on… CWE-502
 Deserialization of Untrusted Data
CVE-2026-42779 2026-05-2 02:55 2026-05-1 Show GitHub Exploit DB Packet Storm
694 5.9 MEDIUM
Network
apache airflow Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between … CWE-295
Improper Certificate Validation 
CVE-2026-41016 2026-05-2 02:54 2026-04-30 Show GitHub Exploit DB Packet Storm
695 9.6 CRITICAL
Network
mozilla firefox
thunderbird
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1. CWE-120
Classic Buffer Overflow
CVE-2026-7321 2026-05-2 02:54 2026-04-29 Show GitHub Exploit DB Packet Storm
696 5.3 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2025-14688 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
697 6.5 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially cra… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2025-36122 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
698 6.5 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-1577 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
699 9.8 CRITICAL
Network
exim exim In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation… CWE-684
CWE-787
 Incorrect Provision of Specified Functionality
 Out-of-bounds Write
CVE-2026-40685 2026-05-2 02:51 2026-05-1 Show GitHub Exploit DB Packet Storm
700 5.5 MEDIUM
Local
opencascade open_cascade_technology An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML… CWE-125
Out-of-bounds Read
CVE-2026-42479 2026-05-2 02:48 2026-05-2 Show GitHub Exploit DB Packet Storm