Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225971 2.9 注意 Wireshark - Wireshark の SDP 解析機能におけるサービス運用妨害 (無限ループ) の脆弱性 CWE-310
暗号の問題
CVE-2013-1576 2013-04-9 16:39 2013-01-29 Show GitHub Exploit DB Packet Storm
225972 2.9 注意 Wireshark - Wireshark の解析エンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-1589 2013-04-9 16:38 2013-01-29 Show GitHub Exploit DB Packet Storm
225973 2.9 注意 Wireshark - Wireshark の NTLMSSP 解析機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1590 2013-04-9 16:33 2013-01-29 Show GitHub Exploit DB Packet Storm
225974 2.9 注意 Wireshark - Wireshark の R3 解析機能におけるサービス運用妨害 (無限ループ) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1575 2013-04-9 16:18 2013-01-29 Show GitHub Exploit DB Packet Storm
225975 5.8 警告 Novell - Mac OS X 上で稼働する Novell OES 用 Novell Kanaka コンポーネントにおけるサーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2013-2770 2013-04-9 16:09 2013-03-15 Show GitHub Exploit DB Packet Storm
225976 2.9 注意 Wireshark - Wireshark の Bluetooth HCI 解析機能におけるサービス運用妨害 (無限ループ) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1574 2013-04-9 16:09 2013-01-29 Show GitHub Exploit DB Packet Storm
225977 3.5 注意 IBM - IBM Scale Out Network Attached Storage における重要なサーバ情報を取得される脆弱性 CWE-255
CWE-264
CVE-2012-0706 2013-04-9 16:08 2013-03-28 Show GitHub Exploit DB Packet Storm
225978 7.2 危険 Linux - Linux Kernel の clone システムコールの実装における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1858 2013-04-9 16:07 2013-03-14 Show GitHub Exploit DB Packet Storm
225979 7.1 危険 Cogent Real-Time Systems Inc. - 複数の Cogent Real-Time Systems 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2013-0683 2013-04-9 16:05 2013-04-5 Show GitHub Exploit DB Packet Storm
225980 7.5 危険 Cogent Real-Time Systems Inc. - 複数の Cogent Real-Time Systems 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-0682 2013-04-9 16:03 2013-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2731 5.3 MEDIUM
Network
uriparser_project uriparser In uriparser before 1.0.2, there is pointer difference truncation to int in various places. CWE-197
 Numeric Truncation Error
CVE-2026-44927 2026-05-13 00:12 2026-05-8 Show GitHub Exploit DB Packet Storm
2732 9.8 CRITICAL
Network
- - Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHan… CWE-22
Path Traversal
CVE-2026-38360 2026-05-13 00:10 2026-05-9 Show GitHub Exploit DB Packet Storm
2733 7.4 HIGH
Local
- - Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-34354 2026-05-13 00:10 2026-05-9 Show GitHub Exploit DB Packet Storm
2734 7.2 HIGH
Network
- - Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI. CWE-22
Path Traversal
CVE-2026-41951 2026-05-13 00:10 2026-05-11 Show GitHub Exploit DB Packet Storm
2735 3.3 LOW
Local
- - The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation fe… CWE-22
Path Traversal
CVE-2026-41530 2026-05-13 00:10 2026-05-12 Show GitHub Exploit DB Packet Storm
2736 7.4 HIGH
Network
- - "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notific… CWE-295
Improper Certificate Validation 
CVE-2026-41872 2026-05-13 00:10 2026-05-12 Show GitHub Exploit DB Packet Storm
2737 - - - Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited… CWE-1392
 Use of Default Credentials
CVE-2026-7428 2026-05-13 00:09 2026-05-12 Show GitHub Exploit DB Packet Storm
2738 8.1 HIGH
Network
- - HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission … CWE-352
 Origin Validation Error
CVE-2026-38566 2026-05-13 00:06 2026-05-12 Show GitHub Exploit DB Packet Storm
2739 9.8 CRITICAL
Network
- - HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker c… CWE-89
SQL Injection
CVE-2026-38567 2026-05-13 00:06 2026-05-12 Show GitHub Exploit DB Packet Storm
2740 6.1 MEDIUM
Network
- - A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in… CWE-79
Cross-site Scripting
CVE-2025-61305 2026-05-13 00:05 2026-05-12 Show GitHub Exploit DB Packet Storm