Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3951 7.5 重要
Network
kiloview E3 Firmware Kiloview Electronics Co., Ltd.のE3 Firmwareにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-63560 2026-02-6 10:40 2025-11-6 Show GitHub Exploit DB Packet Storm
3952 6.5 警告
Network
GuoMinJim PersonManage GuoMinJimのPersonManageにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-63686 2026-02-6 10:40 2025-11-7 Show GitHub Exploit DB Packet Storm
3953 5.4 警告
Network
Magento, Inc. E-Commerce Bhabishya-123のE-commerceにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-63883 2026-02-6 10:40 2025-11-18 Show GitHub Exploit DB Packet Storm
3954 5.3 警告
Network
Salesforce.com, inc. MuleSoft Anypoint Extension Pack Salesforce.com, inc.のMuleSoft Anypoint Extension Packにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2025-64318 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
3955 5.3 警告
Network
Salesforce.com, inc. MuleSoft Anypoint Extension Pack Salesforce.com, inc.のMuleSoft Anypoint Extension Packにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2025-64319 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
3956 6.5 警告
Network
Salesforce.com, inc. Agentforce Vibes Salesforce.com, inc.のAgentforce Vibesにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2025-64320 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
3957 5.3 警告
Network
Salesforce.com, inc. Agentforce Vibes Salesforce.com, inc.のAgentforce Vibesにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2025-64321 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
3958 5.3 警告
Network
Salesforce.com, inc. Agentforce Vibes Salesforce.com, inc.のAgentforce Vibesにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2025-64322 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
3959 5.6 警告
Local
Synology Inc. BeeDrive Synology Inc.のBeeDriveにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2025-8074 2026-02-6 10:40 2025-12-4 Show GitHub Exploit DB Packet Storm
3960 8.8 重要
Network
birkir Prime birkirのPrimeにおける複数の脆弱性 CWE-352
CWE-352
CWE-862
CVE-2026-1169 2026-02-6 10:40 2026-01-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
231 7.5 HIGH
Network
- - Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handle… New CWE-362
Race Condition
CVE-2026-42594 2026-05-15 01:28 2026-05-15 Show GitHub Exploit DB Packet Storm
232 8.6 HIGH
Network
- - Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based S… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42595 2026-05-15 01:28 2026-05-15 Show GitHub Exploit DB Packet Storm
233 - - - CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-sig… New CWE-295
Improper Certificate Validation 
CVE-2026-41132 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
234 6.1 MEDIUM
Network
- - CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests marked the endpoin… New CWE-352
 Origin Validation Error
CVE-2026-41255 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
235 - - - CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in or… New CWE-89
SQL Injection
CVE-2026-42031 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
236 - - - CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authoriza… New CWE-863
 Incorrect Authorization
CVE-2026-42032 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
237 7.5 HIGH
Network
- - Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after bei… New CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2026-42577 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
238 - - - Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explici… New CWE-113
HTTP Response Splitting
CVE-2026-42578 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
239 7.5 HIGH
Network
- - Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encodi… New CWE-20
CWE-400
CWE-626
 Improper Input Validation 
 Uncontrolled Resource Consumption
 Null Byte Interaction Error (Poison Null Byte)
CVE-2026-42579 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm
240 6.5 MEDIUM
Network
- - Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. Th… New CWE-190
CWE-444
 Integer Overflow or Wraparound
HTTP Request Smuggling
CVE-2026-42580 2026-05-15 01:26 2026-05-14 Show GitHub Exploit DB Packet Storm