Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228181 6.1 警告 サン・マイクロシステムズ
レッドハット
VMware
オラクル
- Oracle Java SE の Java Runtime Environment (JRE) コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3555 2012-12-17 17:55 2011-10-18 Show GitHub Exploit DB Packet Storm
228182 5.1 警告 bzip.org
アップル
サイバートラスト株式会社
オラクル
VMware
レッドハット
- bzip2 および libbzip2 の BZ2_decompress 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-0405 2012-12-17 16:47 2010-09-20 Show GitHub Exploit DB Packet Storm
228183 5 警告 VMware
Apache Software Foundation
- Apache Tomcat における IP アドレスおよび HTTP ヘッダ情報を意図せず読み取られる脆弱性 CWE-200
情報漏えい
CVE-2011-3375 2012-12-17 16:35 2012-01-19 Show GitHub Exploit DB Packet Storm
228184 6.8 警告 VMware
RPM
- RPM の headerVerifyInfo 関数におけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-189
数値処理の問題
CVE-2012-0815 2012-12-17 16:33 2012-06-4 Show GitHub Exploit DB Packet Storm
228185 6.8 警告 VMware
RPM
- RPM の headerLoad 関数におけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0061 2012-12-17 16:31 2012-06-4 Show GitHub Exploit DB Packet Storm
228186 7.2 危険 VMware
Linux
- Linux Kernel の robust futex の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-0028 2012-12-17 16:28 2012-06-21 Show GitHub Exploit DB Packet Storm
228187 10 危険 VMware
Linux
- Linux Kernel の CIFSFindNext 関数における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2011-3191 2012-12-17 16:27 2012-05-24 Show GitHub Exploit DB Packet Storm
228188 6.8 警告 VMware
RPM
- RPM におけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0060 2012-12-17 16:26 2012-06-4 Show GitHub Exploit DB Packet Storm
228189 7.5 危険 Gisle Aas
VMware
- Perl 用の Digest モジュールにおける任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-3597 2012-12-17 16:24 2012-01-13 Show GitHub Exploit DB Packet Storm
228190 4.3 警告 Andy Armstrong
VMware
レッドハット
- CGI.pm および CGI::Simple の header 関数における任意のHTTP ヘッダを挿入される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-4410 2012-12-17 16:23 2010-12-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
301 9.9 CRITICAL
Network
- - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field … Update CWE-20
CWE-22
CWE-187
 Improper Input Validation 
Path Traversal
 Partial String Comparison
CVE-2026-35031 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
302 - - - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not val… Update CWE-73
CWE-918
 External Control of File Name or Path
Server-Side Request Forgery (SSRF) 
CVE-2026-35032 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
303 - - - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions que… Update CWE-88
CWE-862
Argument Injection
 Missing Authorization
CVE-2026-35033 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
304 - - - radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in… Update CWE-78
OS Command 
CVE-2026-40499 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
305 - - - Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame h… Update CWE-20
CWE-347
 Improper Input Validation 
 Improper Verification of Cryptographic Signature
CVE-2026-6328 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
306 5.4 MEDIUM
Network
- - Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser. Update CWE-79
Cross-site Scripting
CVE-2026-26291 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
307 7.5 HIGH
Network
- - Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved. Update CWE-670
 Always-Incorrect Control Flow Implementation
CVE-2026-40719 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
308 7.5 HIGH
Network
- - Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::… Update CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-5088 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
309 8.0 HIGH
Network
- - nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting f… Update CWE-1385
 Missing Origin Validation in WebSockets
CVE-2026-35589 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
310 7.2 HIGH
Network
- - BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) … Update CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-39387 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm