Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244561 6.5 警告 LedgerSMB
dws systems inc.
sql-ledger
- LSMB などにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4078 2012-06-26 16:02 2008-09-15 Show GitHub Exploit DB Packet Storm
244562 7.8 危険 LedgerSMB
dws systems inc.
sql-ledger
- LSMB の CGI スクリプトにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-4077 2012-06-26 16:02 2008-08-26 Show GitHub Exploit DB Packet Storm
244563 6.8 警告 Dino - D-iscussion Board の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4075 2012-06-26 16:02 2008-09-15 Show GitHub Exploit DB Packet Storm
244564 5 警告 マイクロソフト
アドビシステムズ
- Adobe Acrobat の特定の ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-4071 2012-06-26 16:02 2008-09-15 Show GitHub Exploit DB Packet Storm
244565 4.3 警告 XOOPS
有限会社ブルームーン
- XOOPS 用の Bluemoon PopnupBLOG モジュールの index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4053 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
244566 9.3 危険 friendly technologies - Friendly Technologies FriendlyPPPoE Client における任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2008-4050 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
244567 6.8 警告 friendly technologies - Friendly Technologies FriendlyPPPoE Client の fwRemoteCfg.dll における任意のプログラムを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-4049 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
244568 6.8 警告 friendly technologies - Friendly Technologies FriendlyPPPoE Client の fwRemoteCfg.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-4048 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
244569 7.5 危険 elitecms - eliteCMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4046 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
244570 4.3 警告 @mail - @Mail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4045 2012-06-26 16:02 2008-09-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
501 9.6 CRITICAL
Network
mozilla firefox
thunderbird
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140… New CWE-416
 Use After Free
CVE-2026-8953 2026-05-20 03:45 2026-05-19 Show GitHub Exploit DB Packet Storm
502 7.5 HIGH
Network
mozilla firefox
thunderbird
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. New CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-8954 2026-05-20 03:42 2026-05-19 Show GitHub Exploit DB Packet Storm
503 4.3 MEDIUM
Network
microsoft 365_apps
office
office_long_term_servicing_channel
word
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. Update CWE-73
 External Control of File Name or Path
CVE-2026-40421 2026-05-20 03:38 2026-05-13 Show GitHub Exploit DB Packet Storm
504 7.8 HIGH
Local
microsoft office
office_long_term_servicing_channel
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Update CWE-122
Heap-based Buffer Overflow
CVE-2026-42831 2026-05-20 03:38 2026-05-13 Show GitHub Exploit DB Packet Storm
505 5.5 MEDIUM
Local
microsoft excel
office
office_long_term_servicing_channel
word
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. Update CWE-284
NVD-CWE-noinfo
Improper Access Control
CVE-2026-42832 2026-05-20 03:38 2026-05-13 Show GitHub Exploit DB Packet Storm
506 7.5 HIGH
Network
h2o h2o A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi… Update CWE-200
CWE-284
NVD-CWE-noinfo
Information Exposure
Improper Access Control
CVE-2026-8750 2026-05-20 03:22 2026-05-17 Show GitHub Exploit DB Packet Storm
507 6.5 MEDIUM
Network
- - Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in t… Update CWE-863
 Incorrect Authorization
CVE-2026-42883 2026-05-20 03:19 2026-05-12 Show GitHub Exploit DB Packet Storm
508 6.2 MEDIUM
Network
- - LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/featur… Update CWE-79
Cross-site Scripting
CVE-2026-42045 2026-05-20 03:19 2026-05-13 Show GitHub Exploit DB Packet Storm
509 9.8 CRITICAL
Network
mozilla firefox Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. Update CWE-693
 Protection Mechanism Failure
CVE-2026-8401 2026-05-20 03:16 2026-05-13 Show GitHub Exploit DB Packet Storm
510 5.3 MEDIUM
Network
mozilla firefox Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. Update CWE-20
CWE-79
CWE-119
 Improper Input Validation 
Cross-site Scripting
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-8391 2026-05-20 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm