Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224081 4 警告 シスコシステムズ - Cisco Unified Computing System の管理 Web インターフェイスにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-4083 2013-09-25 11:29 2013-09-18 Show GitHub Exploit DB Packet Storm
224082 5.8 警告 シスコシステムズ - Cisco Unified Computing System の Serial over LAN サブシステムにおける重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2012-4074 2013-09-25 11:25 2013-09-18 Show GitHub Exploit DB Packet Storm
224083 5.8 警告 シスコシステムズ - Cisco Unified Computing System の クライアントの KVM サブシステムにおけるサーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2012-4073 2013-09-25 11:22 2013-09-18 Show GitHub Exploit DB Packet Storm
224084 4.3 警告 シスコシステムズ - Cisco Unified Computing System の KVM サブシステムにおける SSL サーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2012-4072 2013-09-25 11:17 2013-09-18 Show GitHub Exploit DB Packet Storm
224085 4.3 警告 シスコシステムズ - Cisco Intrusion Prevention System の Web フレームワークの認証管理者プロセスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-287
不適切な認証
CVE-2013-5497 2013-09-25 11:09 2013-09-19 Show GitHub Exploit DB Packet Storm
224086 5.4 警告 シスコシステムズ - Cisco NX-OS の BGP の実装の regex エンジンおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-1121 2013-09-25 10:57 2013-09-17 Show GitHub Exploit DB Packet Storm
224087 4.3 警告 ヒューレット・パッカード - HP XP P9000 Command View Advanced Edition ソフトウェアにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4814 2013-09-25 10:44 2013-09-20 Show GitHub Exploit DB Packet Storm
224088 4.3 警告 ヒューレット・パッカード - HP ArcSight Enterprise Security Manager の Web インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4815 2013-09-25 10:42 2013-09-19 Show GitHub Exploit DB Packet Storm
224089 6.8 警告 GLPI-PROJECT.ORG - GLPI の inc/central.class.php におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-5696 2013-09-25 10:41 2013-09-12 Show GitHub Exploit DB Packet Storm
224090 10 危険 アドビシステムズ - Adobe ColdFusion の認証プロセスにおける管理者権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-5290 2013-09-24 16:41 2010-08-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
791 7.5 HIGH
Network
- - MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth clas… New CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-44847 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
792 8.2 HIGH
Network
- - LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other ap… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-44843 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
793 5.9 MEDIUM
Network
- - view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file … New CWE-187
 Partial String Comparison
CVE-2026-44837 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
794 7.5 HIGH
Network
- - Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass use… New CWE-1336
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-44209 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
795 4.9 MEDIUM
Network
- - Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which a… New CWE-202
 Exposure of Sensitive Information Through Data Queries
CVE-2026-42797 2026-05-27 06:16 2026-05-26 Show GitHub Exploit DB Packet Storm
796 - - - MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The en… New CWE-862
 Missing Authorization
CVE-2026-42337 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
797 - - - MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsi… New CWE-367
CWE-918
 Time-of-check Time-of-use (TOCTOU) Race Condition
Server-Side Request Forgery (SSRF) 
CVE-2026-42336 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
798 - - - MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/o… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42335 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
799 9.8 CRITICAL
Network
- - IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap… New CWE-863
 Incorrect Authorization
CVE-2026-3660 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm
800 - - - AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an ove… New - CVE-2025-68711 2026-05-27 06:16 2026-05-27 Show GitHub Exploit DB Packet Storm