Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244971 7.5 危険 envolution - Envolution の News モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-4253 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244972 4.3 警告 chilkat software - CkString.dll および CHILKAT ASP String の特定の ActiveX コントロールにおける絶対パストラバーサルの脆弱性 - CVE-2007-4252 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244973 5 警告 advanced searchbar - Advanced Searchbar の isChecked 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-4250 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244974 4.3 警告 exportnation - Internet Explorer の ExportNation toolbar におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4249 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244975 4.3 警告 dimema - CDM の Search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4245 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244976 7.8 危険 Astaro - ASG の pfilter-reporter.pl におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4243 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244977 5 警告 Astaro - ASG の pop3 Proxy における本スキャンを回避される脆弱性 - CVE-2007-4242 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244978 4.3 警告 c-sam - C-SAM oneWallet の user/forgotPassStep2.jsp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4239 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244979 5 警告 camera life - Camera Life における非公開の写真をダウンロードされる脆弱性 - CVE-2007-4234 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
244980 4.3 警告 camera life - Camera Life におけるサービス運用妨害の脆弱性 - CVE-2007-4233 2012-06-26 15:54 2007-08-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
451 7.5 HIGH
Network
haxx curl Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the seco… New CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-6276 2026-05-14 23:21 2026-05-13 Show GitHub Exploit DB Packet Storm
452 5.3 MEDIUM
Network
haxx curl When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. New NVD-CWE-noinfo
CVE-2026-6429 2026-05-14 23:18 2026-05-13 Show GitHub Exploit DB Packet Storm
453 5.3 MEDIUM
Network
haxx curl When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and inste… New CWE-295
Improper Certificate Validation 
CVE-2026-7009 2026-05-14 23:17 2026-05-13 Show GitHub Exploit DB Packet Storm
454 7.5 HIGH
Network
vercel next.js Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts wit… New CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-45109 2026-05-14 23:14 2026-05-14 Show GitHub Exploit DB Packet Storm
455 5.3 MEDIUM
Network
haxx curl Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reu… New CWE-294
Authentication Bypass by Capture-replay 
CVE-2026-7168 2026-05-14 23:12 2026-05-13 Show GitHub Exploit DB Packet Storm
456 5.5 MEDIUM
Local
apple macos A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks. New CWE-358
CWE-693
 Improperly Implemented Security Check for Standard
 Protection Mechanism Failure
CVE-2026-28914 2026-05-14 23:02 2026-05-12 Show GitHub Exploit DB Packet Storm
457 7.8 HIGH
Local
apple macos A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able … New CWE-22
Path Traversal
CVE-2026-28915 2026-05-14 23:02 2026-05-12 Show GitHub Exploit DB Packet Storm
458 7.5 HIGH
Network
apple ipados
iphone_os
macos
visionos
watchos
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5,… New CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-28943 2026-05-14 23:02 2026-05-12 Show GitHub Exploit DB Packet Storm
459 5.5 MEDIUM
Local
apple ipados
iphone_os
macos
tvos
visionos
watchos
A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watc… New CWE-362
Race Condition
CVE-2026-28996 2026-05-14 23:01 2026-05-12 Show GitHub Exploit DB Packet Storm
460 7.5 HIGH
Network
apple ipados
iphone_os
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging. New CWE-863
 Incorrect Authorization
CVE-2026-28873 2026-05-14 23:01 2026-05-12 Show GitHub Exploit DB Packet Storm