Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220711 5.5 警告 Puppet - Puppet における他のノードのリソースを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-0528 2014-02-19 18:52 2011-01-27 Show GitHub Exploit DB Packet Storm
220712 9.3 危険 クアルコム - MSM デバイス用 Qualcomm Innovation Center Android コントリビューションなどで使用される Linux Kernel 用 CONFIG_STRICT_MEMORY_RWX の実装におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4737 2014-02-19 18:51 2013-09-5 Show GitHub Exploit DB Packet Storm
220713 5 警告 The PHP Group - PHP の ext/gd/gd.c における重要な情報を取得される脆弱性 CWE-189
数値処理の問題
CVE-2014-2020 2014-02-19 18:36 2014-02-18 Show GitHub Exploit DB Packet Storm
220714 6.4 警告 The PHP Group - PHP の ext/gd/gd.c の gdImageCrop 関数における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2013-7328 2014-02-19 18:33 2013-12-28 Show GitHub Exploit DB Packet Storm
220715 5 警告 The PHP Group - PHP の libxml RSHUTDOWN 機能における open_basedir 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2012-1171 2014-02-19 18:31 2012-03-25 Show GitHub Exploit DB Packet Storm
220716 2.1 注意 ヒューレット・パッカード - HP Linux Imaging and Printing におけるログファイルを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6108 2014-02-19 18:24 2012-11-27 Show GitHub Exploit DB Packet Storm
220717 7.5 危険 netfilter.org - iptables の extensions/libxt_tcp.c におけるファイアウォールの制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2012-2663 2014-02-19 18:23 2012-03-30 Show GitHub Exploit DB Packet Storm
220718 5.7 警告 レッドハット - Red Hat Enterprise Linux の kexec-tools パッケージで配布される kexec-tools 用 Red Hat mkdumprd スクリプトにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2011-3590 2014-02-19 17:52 2011-08-10 Show GitHub Exploit DB Packet Storm
220719 5.7 警告 レッドハット - Red Hat Enterprise Linux の kexec-tools パッケージで配布される kexec-tools 用 Red Hat mkdumprd スクリプトにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2011-3589 2014-02-19 17:51 2011-08-10 Show GitHub Exploit DB Packet Storm
220720 5.7 警告 レッドハット - Red Hat Enterprise Linux の kexec-tools パッケージで配布される kexec-tools 用 Red Hat mkdumprd スクリプトにおける kdump サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2011-3588 2014-02-19 17:50 2011-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2171 8.8 HIGH
Network
- - Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affect… CWE-863
 Incorrect Authorization
CVE-2026-2465 2026-05-13 01:47 2026-05-12 Show GitHub Exploit DB Packet Storm
2172 - - - ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to pe… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44499 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2173 5.3 MEDIUM
Network
- - novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend… CWE-22
Path Traversal
CVE-2026-42028 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2174 7.5 HIGH
Network
- - Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-6659 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2175 - - - Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server co… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-41517 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2176 9.1 CRITICAL
Network
- - Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verif… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-42193 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2177 3.4 LOW
Network
- - draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAut… CWE-200
CWE-601
Information Exposure
Open Redirect
CVE-2026-42195 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2178 8.8 HIGH
Network
- - Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to i… CWE-284
CWE-639
Improper Access Control
 Authorization Bypass Through User-Controlled Key
CVE-2026-42205 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2179 - - - Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing un… CWE-352
 Origin Validation Error
CVE-2026-42286 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2180 - - - Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially… CWE-89
SQL Injection
CVE-2026-42287 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm