Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
236001 4.3 警告 interspire - Interspire Shopping Cart の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1076 2012-09-25 16:59 2008-02-28 Show GitHub Exploit DB Packet Storm
236002 4.3 警告 David Ian Bennett - Maian Cart の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1075 2012-09-25 16:59 2008-02-28 Show GitHub Exploit DB Packet Storm
236003 5 警告 intervideo - InterVideo WinDVD Media Center などにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-1062 2012-09-25 16:59 2008-02-28 Show GitHub Exploit DB Packet Storm
236004 7.8 危険 OpenBSD - OpenBSD の netinet/tcp_subr.c の tcp_respond 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-1058 2012-09-25 16:59 2008-02-22 Show GitHub Exploit DB Packet Storm
236005 7.8 危険 OpenBSD - OpenBSD の netinet6/ip6_input.c の ip6_check_rh0hdr 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-1057 2012-09-25 16:59 2008-02-25 Show GitHub Exploit DB Packet Storm
236006 7.5 危険 Netwin Ltd - NetWin SurgeMail および WebMail の webmail.exe におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2008-1055 2012-09-25 16:59 2008-02-27 Show GitHub Exploit DB Packet Storm
236007 6.4 警告 Netwin Ltd - NetWin SurgeMail の _lib_spawn_user_getpid 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1054 2012-09-25 16:59 2008-02-27 Show GitHub Exploit DB Packet Storm
236008 6.4 警告 Netwin Ltd - NetWin SurgeFTP の管理 Web インターフェースにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-1052 2012-09-25 16:59 2008-02-27 Show GitHub Exploit DB Packet Storm
236009 5 警告 MoinMoin - MoinMoin の wikimacro.py における保護されたページを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1099 2012-09-25 16:59 2007-08-30 Show GitHub Exploit DB Packet Storm
236010 4.3 警告 MoinMoin - MoinMoin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1098 2012-09-25 16:59 2007-08-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
651 9.6 CRITICAL
Network
- - SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The applica… New CWE-89
SQL Injection
CVE-2026-34260 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
652 6.3 MEDIUM
Network
- - Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact o… New CWE-862
 Missing Authorization
CVE-2026-40133 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
653 4.3 MEDIUM
Network
- - Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operatio… New CWE-862
 Missing Authorization
CVE-2026-40134 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
654 6.5 MEDIUM
Network
- - An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially c… New CWE-77
Command Injection
CVE-2026-40135 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
655 4.3 MEDIUM
Network
- - SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromis… New CWE-404
 Improper Resource Shutdown or Release
CVE-2026-40136 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
656 6.1 MEDIUM
Network
- - SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially e… New CWE-79
Cross-site Scripting
CVE-2026-40137 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
657 7.5 HIGH
Network
- - The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual res… New CWE-476
 NULL Pointer Dereference
CVE-2025-40833 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
658 8.3 HIGH
Adjacent
- - A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All version… New CWE-321
 Use of Hard-coded Cryptographic Key
CVE-2025-40946 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
659 9.1 CRITICAL
Network
- - A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion… New CWE-306
Missing Authentication for Critical Function
CVE-2026-22924 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm
660 7.5 HIGH
Network
- - A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This cou… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-22925 2026-05-12 23:19 2026-05-12 Show GitHub Exploit DB Packet Storm