Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229401 7.6 危険 サン・マイクロシステムズ
VMware
レッドハット
- 複数の Oracle 製品の Java Runtime Environment における脆弱性 CWE-noinfo
情報不足
CVE-2010-4451 2012-12-18 12:13 2011-02-15 Show GitHub Exploit DB Packet Storm
229402 5 警告 サイバートラスト株式会社
VMware
Python Software Foundation
レッドハット
- Python の audioop モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-2089 2012-12-18 12:05 2010-01-11 Show GitHub Exploit DB Packet Storm
229403 5 警告 サイバートラスト株式会社
VMware
Python Software Foundation
レッドハット
- Python の audioop モジュール内にある audioop.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-1634 2012-12-18 12:04 2010-05-27 Show GitHub Exploit DB Packet Storm
229404 5 警告 Expat
IBM
Apache Software Foundation
サイバートラスト株式会社
サン・マイクロシステムズ
ヒューレット・パッカード
VMware
レッドハット
- Expat の big2_toUtf8 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-3560 2012-12-18 12:01 2009-12-4 Show GitHub Exploit DB Packet Storm
229405 6.4 警告 サイバートラスト株式会社
VMware
Python Software Foundation
レッドハット
- Python の urllib および urllib2 モジュールにおける重要な情報を取得される脆弱性 CWE-399
リソース管理の問題
CVE-2011-1521 2012-12-18 11:37 2011-05-15 Show GitHub Exploit DB Packet Storm
229406 10 危険 アドビシステムズ - Adobe Photoshop Camera Raw におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-5680 2012-12-18 10:41 2012-12-12 Show GitHub Exploit DB Packet Storm
229407 2.1 注意 ヒューレット・パッカード - Itanium および Alpha プラットフォーム上の HP OpenVMS におけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2012-3276 2012-12-18 10:39 2012-12-10 Show GitHub Exploit DB Packet Storm
229408 5 警告 GNU Project
VMware
- GnuTLS におけるサービス運用妨害 (ヒープメモリ破損およびアプリケーションクラッシュ) の脆弱性 CWE-310
暗号の問題
CVE-2012-1573 2012-12-17 18:09 2012-03-21 Show GitHub Exploit DB Packet Storm
229409 5 警告 GNU Project
VMware
- GnuTLS で使用される GNU Libtasn1 におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2012-1569 2012-12-17 18:08 2012-03-21 Show GitHub Exploit DB Packet Storm
229410 4.3 警告 GNU Project
VMware
- GnuTLS の gnutls_session_get_data 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-4128 2012-12-17 18:07 2011-11-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 6.5 MEDIUM
Local
- - In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading … New CWE-150
 Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2026-41526 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
212 6.5 MEDIUM
Local
- - KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of … New CWE-669
 Incorrect Resource Transfer Between Spheres
CVE-2026-41525 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
213 5.9 MEDIUM
Network
- - In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conv… New CWE-284
Improper Access Control
CVE-2026-40966 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
214 - - - Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to prot… New CWE-306
Missing Authentication for Critical Function
CVE-2024-54013 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
215 - - - Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be e… New CWE-78
OS Command 
CVE-2024-54012 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
216 - - - Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has r… New CWE-20
 Improper Input Validation 
CVE-2024-54011 2026-04-28 17:15 2026-04-28 Show GitHub Exploit DB Packet Storm
217 7.3 HIGH
Network
- - A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of th… New CWE-22
Path Traversal
CVE-2026-7234 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
218 3.3 LOW
Local
- - A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulatio… New CWE-119
CWE-125
Incorrect Access of Indexable Resource ('Range Error') 
Out-of-bounds Read
CVE-2026-7233 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
219 4.3 MEDIUM
Network
- - A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attac… New CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-7230 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
220 6.3 MEDIUM
Network
- - A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manip… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7229 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm