Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225171 5 警告 Google - Google Chrome におけるポップアップブロッカーを回避される脆弱性 CWE-noinfo
情報不足
CVE-2012-2892 2012-12-26 18:05 2012-09-25 Show GitHub Exploit DB Packet Storm
225172 5 警告 Google - Google Chrome の IPC の実装における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2891 2012-12-26 18:04 2012-09-25 Show GitHub Exploit DB Packet Storm
225173 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2888 2012-12-26 18:02 2012-09-25 Show GitHub Exploit DB Packet Storm
225174 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2887 2012-12-26 18:01 2012-09-25 Show GitHub Exploit DB Packet Storm
225175 4.3 警告 Google - Google Chrome におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2886 2012-12-26 18:00 2012-09-25 Show GitHub Exploit DB Packet Storm
225176 2.6 注意 VMware
Python Software Foundation
- Python SimpleHTTPServer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4940 2012-12-26 18:00 2012-06-19 Show GitHub Exploit DB Packet Storm
225177 7.5 危険 Google - Google Chrome におけるメモリ二重解放の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2885 2012-12-26 17:59 2012-09-25 Show GitHub Exploit DB Packet Storm
225178 5 警告 Google - Google Chrome で使用される Skia におけるサービス運用妨害 (out-of-bounds read) の脆弱性 CWE-119
バッファエラー
CVE-2012-2884 2012-12-26 17:58 2012-09-25 Show GitHub Exploit DB Packet Storm
225179 4.6 警告 GNU Project
VMware
- GNU C Library の stdlib における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-3480 2012-12-26 17:57 2012-08-25 Show GitHub Exploit DB Packet Storm
225180 3.3 注意 GNU Project
VMware
- GNU C Library の addmntent 関数における /etc/mtab ファイルの破損を誘発される脆弱性 CWE-16
環境設定
CVE-2011-1089 2012-12-26 17:55 2011-04-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
551 7.5 HIGH
Network
- - pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystem… New CWE-22
Path Traversal
CVE-2026-42351 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
552 - - - Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo que… New CWE-601
Open Redirect
CVE-2026-42350 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
553 6.5 MEDIUM
Network
- - Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fundamental TOCTOU (Time-of-Check-Time-of-Use) vulner… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42346 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
554 7.7 HIGH
Network
- - FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a full… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42345 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
555 6.3 MEDIUM
Network
- - FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding (TOCTOU — Tim… New CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-42344 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
556 - - - FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service rel… New CWE-400
 Uncontrolled Resource Consumption
CVE-2026-42343 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
557 4.4 MEDIUM
Local
- - Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a cr… New CWE-78
OS Command 
CVE-2026-42307 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
558 9.8 CRITICAL
Network
- - FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The star… New CWE-306
Missing Authentication for Critical Function
CVE-2026-42302 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
559 10.0 CRITICAL
Network
- - Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows a… New CWE-94
Code Injection
CVE-2026-42298 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
560 6.8 MEDIUM
Network
- - SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly au… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-42291 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm