Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248521 5 警告 PHPNUKE - Francisco Burzi PHP-Nuke における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3784 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248522 5 警告 phpMyFAQ - phpMyFAQ における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3783 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248523 5 警告 Tecnick.com - TCExam における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3806 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248524 5 警告 taskfreak - TaskFreak! multi-mysql における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3805 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248525 5 警告 Basic-CMS - SweetRice における 重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3804 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248526 5 警告 SugarCRM - SugarCRM における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3803 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248527 5 警告 Status - StatusNet における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3802 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248528 5 警告 simpletest - SimpleTest における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3801 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248529 5 警告 s9y - Serendipity における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3800 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
248530 5 警告 php link directory - phpLD における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3782 2012-03-27 18:43 2011-09-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
231 - - - Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e… New CWE-603
 Use of Client-Side Authentication
CVE-2026-42098 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
232 - - - Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves… New CWE-362
Race Condition
CVE-2026-42099 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
233 - - - Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Clou… New CWE-228
 Improper Handling of Syntactically Invalid Structure
CVE-2026-42100 2026-05-19 23:45 2026-05-19 Show GitHub Exploit DB Packet Storm
234 3.9 LOW
Local
- - FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app… New CWE-79
Cross-site Scripting
CVE-2026-27964 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
235 6.5 MEDIUM
Network
- - FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta… New CWE-200
CWE-212
Information Exposure
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-27892 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
236 5.3 MEDIUM
Network
- - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv… New CWE-200
CWE-524
CWE-672
Information Exposure
 Use of Cache Containing Sensitive Information
 Operation on a Resource after Expiration or Release
CVE-2026-32244 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
237 - - - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature… New CWE-862
 Missing Authorization
CVE-2026-33514 2026-05-19 23:44 2026-05-19 Show GitHub Exploit DB Packet Storm
238 10.0 CRITICAL
Network
- - HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-43633 2026-05-19 23:43 2026-05-19 Show GitHub Exploit DB Packet Storm
239 6.5 MEDIUM
Network
vercel turborepo Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the l… New CWE-352
CWE-384
 Origin Validation Error
 Session Fixation
CVE-2026-45773 2026-05-19 23:41 2026-05-16 Show GitHub Exploit DB Packet Storm
240 9.8 CRITICAL
Network
vercel turborepo Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted reposi… New CWE-426
 Untrusted Search Path
CVE-2026-45772 2026-05-19 23:41 2026-05-16 Show GitHub Exploit DB Packet Storm