Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247111 5 警告 Canonical - Ubuntu で使用される Update Manager におけるレポジトリ証明書を読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-0949 2012-06-4 14:03 2012-05-31 Show GitHub Exploit DB Packet Storm
247112 10 危険 Mozilla Foundation - 複数の Mozilla 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2012-0444 2012-06-1 14:19 2012-01-31 Show GitHub Exploit DB Packet Storm
247113 7.8 危険 シスコシステムズ - Cisco ASR 9000 および CRS シリーズの Cisco IOS XR におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-2488 2012-06-1 14:14 2012-05-30 Show GitHub Exploit DB Packet Storm
247114 6.8 警告 TYPO3 Association - TYPO3 の fileDenyPattern 機能におけるアクセス制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2010-5099 2012-06-1 13:50 2010-12-16 Show GitHub Exploit DB Packet Storm
247115 2.6 注意 株式会社バンダイナムコゲームス - 魔法少女まどか☆マギカ iP for Android における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2012-2630 2012-06-1 12:04 2012-06-1 Show GitHub Exploit DB Packet Storm
247116 7.5 危険 Segue Project - Segue における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1255 2012-06-1 12:03 2012-06-1 Show GitHub Exploit DB Packet Storm
247117 4.3 警告 Segue Project - Segue におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1254 2012-06-1 12:02 2012-06-1 Show GitHub Exploit DB Packet Storm
247118 7.5 危険 Jaow - Jaow の add_ons.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2952 2012-05-31 14:52 2012-05-29 Show GitHub Exploit DB Packet Storm
247119 7.5 危険 Plogger Project - Plogger の plog-rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2951 2012-05-31 14:52 2012-05-29 Show GitHub Exploit DB Packet Storm
247120 3.3 注意 Puppet - Puppet および Puppet Enterprise における任意のファイルを上書きされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1906 2012-05-31 14:25 2012-05-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 8.8 HIGH
Network
anthropic claude_code In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposi… Update CWE-20
CWE-77
NVD-CWE-noinfo
 Improper Input Validation 
Command Injection
CVE-2026-40068 2026-05-13 01:21 2026-05-6 Show GitHub Exploit DB Packet Storm
412 6.5 MEDIUM
Network
langgenius dify Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplyin… Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41950 2026-05-13 01:20 2026-05-6 Show GitHub Exploit DB Packet Storm
413 7.5 HIGH
Network
openmrs openmrs OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnera… Update CWE-22
Path Traversal
CVE-2026-40075 2026-05-13 01:18 2026-05-6 Show GitHub Exploit DB Packet Storm
414 8.1 HIGH
Network
getgrav grav Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existi… New CWE-269
CWE-285
CWE-639
CWE-837
 Improper Privilege Management
Improper Authorization
 Authorization Bypass Through User-Controlled Key
 Improper Enforcement of a Single, Unique Action
CVE-2026-42609 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
415 6.5 MEDIUM
Network
getgrav grav Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing … New CWE-863
 Incorrect Authorization
CVE-2026-42610 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
416 8.9 HIGH
Network
getgrav grav Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated t… New CWE-79
Cross-site Scripting
CVE-2026-42611 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
417 5.4 MEDIUM
Network
getgrav grav Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue … New CWE-79
Cross-site Scripting
CVE-2026-42612 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
418 4.8 MEDIUM
Network
getgrav grav Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML thro… New CWE-79
Cross-site Scripting
CVE-2026-42841 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
419 9.6 CRITICAL
Network
- - On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate … New CWE-506
 Embedded Malicious Code
CVE-2026-45321 2026-05-13 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
420 8.1 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in… New CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43938 2026-05-13 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm