Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225121 6.5 警告 Open Constructor - Open Constructor における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-3873 2013-01-4 14:47 2012-12-28 Show GitHub Exploit DB Packet Storm
225122 4.3 警告 Open Constructor - Open Constructor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3872 2013-01-4 14:46 2012-12-28 Show GitHub Exploit DB Packet Storm
225123 3.5 注意 Open Constructor - Open Constructor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3871 2013-01-4 14:22 2012-12-28 Show GitHub Exploit DB Packet Storm
225124 3.5 注意 Open Constructor - Open Constructor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3870 2013-01-4 14:22 2012-12-28 Show GitHub Exploit DB Packet Storm
225125 3.3 注意 サムスン - 複数の Samsung Galaxy デバイス上の Android 用 SamsungDive におけるデバイスの発見を妨害される脆弱性 CWE-200
情報漏えい
CVE-2012-6337 2013-01-4 14:07 2012-12-31 Show GitHub Exploit DB Packet Storm
225126 3.3 注意 Lookout Mobile Security - Lookout の端末捜索機能における任意の位置データに偽装される脆弱性 CWE-noinfo
情報不足
CVE-2012-6336 2013-01-4 14:04 2012-12-31 Show GitHub Exploit DB Packet Storm
225127 3.3 注意 AVG Technologies - Android 用 AVG AntiVirus の Anti-theft サービスにおける任意の位置データに偽装される脆弱性 CWE-noinfo
情報不足
CVE-2012-6335 2013-01-4 14:03 2012-12-31 Show GitHub Exploit DB Packet Storm
225128 5.8 警告 IBM - IBM Security AppScan Enterprise および Rational Policy Tester における SSL サーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2012-0741 2013-01-4 12:09 2012-12-28 Show GitHub Exploit DB Packet Storm
225129 5.8 警告 IBM - IBM Security AppScan Enterprise および Rational Policy Tester における SSL サーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2012-0738 2013-01-4 12:08 2012-12-28 Show GitHub Exploit DB Packet Storm
225130 5 警告 IBM
Apache Software Foundation
富士通
サイバートラスト株式会社
ヒューレット・パッカード
ターボリナックス
オラクル
日立
レッドハット
- Apache Portable Utility ライブラリの apr_brigade_split_line 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-1623 2012-12-28 18:39 2010-10-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
191 8.8 HIGH
Network
- - AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}… New CWE-22
Path Traversal
CVE-2026-42605 2026-05-12 01:17 2026-05-10 Show GitHub Exploit DB Packet Storm
192 - - - ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the craw… New CWE-88
Argument Injection
CVE-2026-42601 2026-05-12 01:17 2026-05-10 Show GitHub Exploit DB Packet Storm
193 - - - Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts, and 2.17.0, the generated authentication filter … New CWE-200
Information Exposure
CVE-2026-42333 2026-05-12 01:17 2026-05-10 Show GitHub Exploit DB Packet Storm
194 - - - Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact re… New CWE-522
 Insufficiently Protected Credentials
CVE-2026-42295 2026-05-12 01:17 2026-05-9 Show GitHub Exploit DB Packet Storm
195 - - - SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor ID… New CWE-400
CWE-611
CWE-776
 Uncontrolled Resource Consumption
XXE
XML Entity Expansion
CVE-2026-42212 2026-05-12 01:17 2026-05-9 Show GitHub Exploit DB Packet Storm
196 7.5 HIGH
Network
- - Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malici… New CWE-770
CWE-789
 Allocation of Resources Without Limits or Throttling
 Memory Allocation with Excessive Size Value
CVE-2026-42189 2026-05-12 01:17 2026-05-9 Show GitHub Exploit DB Packet Storm
197 7.5 HIGH
Network
- - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an infinite recursive loo… New CWE-674
 Uncontrolled Recursion
CVE-2026-41311 2026-05-12 01:17 2026-05-9 Show GitHub Exploit DB Packet Storm
198 7.2 HIGH
Network
- - Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can e… New CWE-78
OS Command 
CVE-2026-3828 2026-05-12 01:17 2026-05-9 Show GitHub Exploit DB Packet Storm
199 - - - Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitat… New CWE-79
Cross-site Scripting
CVE-2026-3320 2026-05-12 01:17 2026-05-12 Show GitHub Exploit DB Packet Storm
200 - - - Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploi… New CWE-79
Cross-site Scripting
CVE-2026-3319 2026-05-12 01:17 2026-05-12 Show GitHub Exploit DB Packet Storm