Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247451 9.3 危険 Novell - Novell iPrint Client の nipplib.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-1702 2012-03-27 18:43 2011-06-6 Show GitHub Exploit DB Packet Storm
247452 9.3 危険 Novell - Novell iPrint Client の nipplib.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-1701 2012-03-27 18:43 2011-06-6 Show GitHub Exploit DB Packet Storm
247453 9.3 危険 Novell - Novell iPrint Client の nipplib.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-1700 2012-03-27 18:43 2011-06-6 Show GitHub Exploit DB Packet Storm
247454 9.3 危険 Novell - Novell iPrint Client の nipplib.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-1699 2012-03-27 18:43 2011-06-6 Show GitHub Exploit DB Packet Storm
247455 4.3 警告 Best Practical Solutions - Best Practical Solutions RT における任意のサーバへ資格情報を送信させる脆弱性 CWE-255
証明書・パスワード管理
CVE-2011-1690 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
247456 4.3 警告 Best Practical Solutions - Best Practical Solutions RT におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-1689 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
247457 4.3 警告 Best Practical Solutions - Best Practical Solutions RT におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-1688 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
247458 4 警告 Best Practical Solutions - Best Practical Solutions RT における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-1687 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
247459 6.5 警告 Best Practical Solutions - Best Practical Solutions RT における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-1686 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
247460 4.6 警告 Best Practical Solutions - Best Practical Solutions RT における任意のコードを実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-1685 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
131 6.1 MEDIUM
Network
- - In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was direc… New CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2026-41575 2026-05-9 01:08 2026-05-9 Show GitHub Exploit DB Packet Storm
132 9.0 CRITICAL
Network
- - RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-41588 2026-05-9 01:08 2026-05-9 Show GitHub Exploit DB Packet Storm
133 6.5 MEDIUM
Network
- - Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3… New CWE-22
CWE-74
Path Traversal
Injection
CVE-2026-41691 2026-05-9 01:05 2026-05-8 Show GitHub Exploit DB Packet Storm
134 4.7 MEDIUM
Network
- - i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and… New CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-41692 2026-05-9 01:05 2026-05-8 Show GitHub Exploit DB Packet Storm
135 - - - SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. New - CVE-2024-33724 2026-05-9 01:04 2026-05-8 Show GitHub Exploit DB Packet Storm
136 - - - Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers … New - CVE-2026-37431 2026-05-9 01:03 2026-05-9 Show GitHub Exploit DB Packet Storm
137 - - - Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-enc… New CWE-178
CWE-436
 Improper Handling of Case Sensitivity
 Interpretation Conflict
CVE-2026-42272 2026-05-9 01:03 2026-05-8 Show GitHub Exploit DB Packet Storm
138 - - - Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are cas… New CWE-178
CWE-436
 Improper Handling of Case Sensitivity
 Interpretation Conflict
CVE-2026-42273 2026-05-9 01:03 2026-05-8 Show GitHub Exploit DB Packet Storm
139 - - - Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstre… New CWE-35
CWE-436
 Path Traversal: '.../...//'
 Interpretation Conflict
CVE-2026-42274 2026-05-9 01:03 2026-05-8 Show GitHub Exploit DB Packet Storm
140 7.5 HIGH
Network
coredns.io coredns CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QU… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-32934 2026-05-9 01:03 2026-05-6 Show GitHub Exploit DB Packet Storm