Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247831 10 危険 サイバートラスト株式会社
ターボリナックス
レッドハット
- Info-ZIP Zip のファイル名やパス名の解析処理におけるバッファオーバーフローの脆弱性 - CVE-2004-1010 2012-04-18 14:32 2004-11-3 Show GitHub Exploit DB Packet Storm
247832 6.4 警告 アップル
サイバートラスト株式会社
Mozilla Foundation
VMware
レッドハット
- Mozilla NSS における X.509 証明書を偽装される脆弱性 CWE-310
暗号の問題
CVE-2009-2409 2012-04-18 10:03 2009-07-30 Show GitHub Exploit DB Packet Storm
247833 3.5 注意 サン・マイクロシステムズ
Quagga
サイバートラスト株式会社
レッドハット
- Quagga の bgpd におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-4826 2012-04-17 18:25 2007-09-7 Show GitHub Exploit DB Packet Storm
247834 5 警告 Quagga
レッドハット
- Quagga の bgpd におけるサービス運用妨害(Null ポインタデリファレンスおよびアプリケーションクラッシュ)の脆弱性 CWE-Other
その他
CVE-2010-1674 2012-04-17 18:23 2011-03-29 Show GitHub Exploit DB Packet Storm
247835 5 警告 Quagga
レッドハット
- Quagga の bgpd におけるサービス運用妨害 (セッションリセット) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-1675 2012-04-17 18:22 2011-03-29 Show GitHub Exploit DB Packet Storm
247836 6.5 警告 Quagga
サイバートラスト株式会社
レッドハット
- Quagga の bgpd の bgp_route_refresh_receive 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-2948 2012-04-17 18:20 2010-08-19 Show GitHub Exploit DB Packet Storm
247837 5 警告 Quagga
レッドハット
- Quagga の bgpd におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-2949 2012-04-17 18:19 2010-08-19 Show GitHub Exploit DB Packet Storm
247838 4.3 警告 Artifex Software - Ghostscript の gs_type2_interpret 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-4054 2012-04-17 17:38 2010-10-23 Show GitHub Exploit DB Packet Storm
247839 9.3 危険 アップル
レッドハット
- 複数の Apple 製品の LIBTIFF におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0192 2012-04-17 17:32 2011-03-3 Show GitHub Exploit DB Packet Storm
247840 4.3 警告 LibTIFF
レッドハット
- LibTIFF の tiffdump.c 内にある ReadDirectory 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-4665 2012-04-17 17:30 2011-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1421 5.4 MEDIUM
Network
- - Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email bo… Update CWE-79
Cross-site Scripting
CVE-2026-42192 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
1422 - - - SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor ID… Update CWE-400
CWE-611
CWE-776
 Uncontrolled Resource Consumption
XXE
XML Entity Expansion
CVE-2026-42212 2026-05-13 01:43 2026-05-9 Show GitHub Exploit DB Packet Storm
1423 - - - SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor f… Update CWE-22
CWE-200
CWE-295
CWE-918
Path Traversal
Information Exposure
Improper Certificate Validation 
Server-Side Request Forgery (SSRF) 
CVE-2026-42213 2026-05-13 01:43 2026-05-9 Show GitHub Exploit DB Packet Storm
1424 6.8 MEDIUM
Network
- - There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. Update CWE-284
Improper Access Control
CVE-2026-1749 2026-05-13 01:42 2026-05-9 Show GitHub Exploit DB Packet Storm
1425 5.3 MEDIUM
Adjacent
- - Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to… Update - CVE-2026-32683 2026-05-13 01:42 2026-05-9 Show GitHub Exploit DB Packet Storm
1426 7.2 HIGH
Network
- - Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can e… Update CWE-78
OS Command 
CVE-2026-3828 2026-05-13 01:42 2026-05-9 Show GitHub Exploit DB Packet Storm
1427 - - - FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service rel… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-42343 2026-05-13 01:41 2026-05-9 Show GitHub Exploit DB Packet Storm
1428 7.5 HIGH
Network
- - pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystem… Update CWE-22
Path Traversal
CVE-2026-42351 2026-05-13 01:41 2026-05-9 Show GitHub Exploit DB Packet Storm
1429 8.6 HIGH
Network
- - pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to reques… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42352 2026-05-13 01:41 2026-05-9 Show GitHub Exploit DB Packet Storm
1430 8.1 HIGH
Network
- - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled… Update CWE-304
 Missing Critical Step in Authentication
CVE-2026-42452 2026-05-13 01:40 2026-05-9 Show GitHub Exploit DB Packet Storm