Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
236841 7.5 危険 jetbox - Jetbox CMS の index.php における SQL インジェクションの脆弱性 - CVE-2007-2685 2012-09-25 16:47 2007-05-21 Show GitHub Exploit DB Packet Storm
236842 5 警告 jetbox - Jetbox CMS における重要な情報を取得される脆弱性 - CVE-2007-2684 2012-09-25 16:47 2007-05-21 Show GitHub Exploit DB Packet Storm
236843 7.5 危険 netsprint - Netsprint Toolbar の toolbar.dll におけるバッファオーバーフローの脆弱性 - CVE-2007-2678 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236844 7.5 危険 open translation engine - OTE の skins/header.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2676 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236845 7.1 危険 Mozilla Foundation - Mozilla Firefox におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2671 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236846 7.6 危険 Don Ho
scintilla
- notepad++ で使用される Scintilla の LexRuby.cxx におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2666 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236847 7.5 危険 php firstpost - PhpFirstPost の block.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2665 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236848 3.5 注意 MySQL AB - MySQL におけるパーティションで区切られたテーブルから重要な情報を取得される脆弱性 - CVE-2007-2693 2012-09-25 16:47 2006-10-26 Show GitHub Exploit DB Packet Storm
236849 7.8 危険 idautomation - IDAutomationLinear6.dll の ID Automation Linear Barcode ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2658 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
236850 7.8 危険 ヒューレット・パッカード - hpqvwocx.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2656 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
111 - - - Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_sh… New CWE-94
CWE-502
Code Injection
 Deserialization of Untrusted Data
CVE-2026-41486 2026-05-9 07:16 2026-05-9 Show GitHub Exploit DB Packet Storm
112 7.5 HIGH
Network
- - The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). New - CVE-2026-39836 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
113 5.3 MEDIUM
Network
- - ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitize… New - CVE-2026-39825 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
114 5.3 MEDIUM
Local
- - The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one… New - CVE-2026-39819 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
115 5.9 MEDIUM
Local
- - The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" su… New - CVE-2026-39817 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
116 9.8 CRITICAL
Network
- - NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. New CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2025-63704 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
117 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix memory leak on failure path cfg80211_inform_bss_frame() may return NULL on failure. In that case, the all… Update CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-43225 2026-05-9 06:22 2026-05-6 Show GitHub Exploit DB Packet Storm
118 8.1 HIGH
Network
- - MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing Authent… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-44400 2026-05-9 06:16 2026-05-9 Show GitHub Exploit DB Packet Storm
119 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hfs: Replace BUG_ON with error handling for CNID count checks In a06ec283e125 next_id, folder_count, and file_count in the super … Update CWE-617
 Reachable Assertion
CVE-2026-43228 2026-05-9 06:16 2026-05-6 Show GitHub Exploit DB Packet Storm
120 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix URB leak in pvr2_send_request_ex When pvr2_send_request_ex() submits a write URB successfully but fails to su… Update CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-43223 2026-05-9 06:14 2026-05-6 Show GitHub Exploit DB Packet Storm