Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
221981 4.3 警告 レッドハット - Red Hat Enterprise Virtualization Manager のリモートビューアにおける SPICE サーバになりすまされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6434 2014-01-27 17:54 2014-01-21 Show GitHub Exploit DB Packet Storm
221982 5.8 警告 アップル - Apple iTunes におけるコンテンツを偽装される脆弱性 CWE-310
暗号の問題
CVE-2014-1242 2014-01-27 17:09 2014-01-22 Show GitHub Exploit DB Packet Storm
221983 2.1 注意 Almanah Project - Almanah Diary における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-1853 2014-01-27 15:56 2013-03-4 Show GitHub Exploit DB Packet Storm
221984 6.8 警告 SpringSource - Spring Framework の Spring MVC における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7315 2014-01-27 15:39 2013-08-22 Show GitHub Exploit DB Packet Storm
221985 10 危険 アドビシステムズ - Adobe Digital Editions における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-0494 2014-01-27 15:11 2014-01-22 Show GitHub Exploit DB Packet Storm
221986 6.8 警告 シスコシステムズ - Cisco Video Surveillance Operations Manager における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2014-0674 2014-01-27 14:48 2014-01-24 Show GitHub Exploit DB Packet Storm
221987 7.5 危険 レッドハット - Red Hat Certificate System および Dogtag Certificate System の Token Processing System におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2013-1886 2014-01-27 14:48 2013-05-22 Show GitHub Exploit DB Packet Storm
221988 4.3 警告 レッドハット - Red Hat Certificate System および Dogtag Certificate System の Token Processing System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1885 2014-01-27 14:47 2013-05-22 Show GitHub Exploit DB Packet Storm
221989 6.8 警告 日本電気 - 複数の NEC 製のルータの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7314 2014-01-27 14:39 2013-08-1 Show GitHub Exploit DB Packet Storm
221990 5.4 警告 Enterasys Networks - Enterasys のスイッチおよびルータの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7312 2014-01-27 14:33 2013-08-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2091 - - - Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or gues… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-44776 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2092 - - - Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from an… CWE-306
Missing Authentication for Critical Function
CVE-2026-44775 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2093 4.3 MEDIUM
Network
- - The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-44749 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2094 6.8 MEDIUM
Network
- - Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enf… CWE-283
CWE-287
 Unverified Ownership
Improper Authentication
CVE-2026-44707 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2095 8.5 HIGH
Network
- - Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da… CWE-89
SQL Injection
CVE-2026-44706 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2096 8.7 HIGH
Network
- - FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview f… CWE-79
Cross-site Scripting
CVE-2026-44669 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2097 6.5 MEDIUM
Network
- - e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by othe… CWE-284
CWE-639
Improper Access Control
 Authorization Bypass Through User-Controlled Key
CVE-2026-43934 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2098 3.5 LOW
Network
- - Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when a receiver who specifies "--output <dir>" w… CWE-22
Path Traversal
CVE-2026-42448 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2099 6.5 MEDIUM
Network
- - libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. At… CWE-416
 Use After Free
CVE-2026-41401 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2100 4.4 MEDIUM
Network
- - nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-41164 2026-05-27 03:16 2026-05-27 Show GitHub Exploit DB Packet Storm