Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3711 7.1 重要
Adjacent
Linux Foundation automotive grade linux Linux FoundationのAutomotive Grade Linuxにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-37532 2026-05-18 11:23 2026-05-1 Show GitHub Exploit DB Packet Storm
3712 8.8 重要
Network
マイクロソフト Microsoft Data Formulator Microsoft Data Formulator のリモートでコードが実行される脆弱性 CWE-94
コード・インジェクション
CVE-2026-41094 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3713 9.1 緊急
Network
マイクロソフト Microsoft Confluence SAML SSO plugin
Microsoft JIRA SAML SSO plugin
Jira と Confluence 用の Microsoft SSO プラグインの特権昇格の脆弱性 CWE-303
CWE-Other
CVE-2026-41103 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3714 5.9 警告
Network
opentelemetry OpenTelemetry.Resources.Azure opentelemetryのOpenTelemetry.Resources.Azureにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41483 2026-05-18 11:22 2026-05-6 Show GitHub Exploit DB Packet Storm
3715 5.9 警告
Network
opentelemetry OpenTelemetry.Exporter.OneCollector opentelemetryのOpenTelemetry.Exporter.OneCollectorにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41484 2026-05-18 11:22 2026-05-6 Show GitHub Exploit DB Packet Storm
3716 5.5 警告
Local
マイクロソフト Visual Studio Code - Live Preview extension マイクロソフトのVisual Studio Code - Live Preview extensionにおける複数の脆弱性 CWE-22
CWE-22
CWE-23
CVE-2026-41612 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3717 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-43903 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3718 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-43904 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3719 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-43905 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3720 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-43906 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312601 6.5 MEDIUM
Network
apache qpid-cpp qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . CWE-20
 Improper Input Validation 
CVE-2009-5004 2024-11-21 10:10 2019-11-9 Show GitHub Exploit DB Packet Storm
312602 6.1 MEDIUM
Network
pixelpost pixelpost pixelpost 1.7.1 has XSS CWE-79
Cross-site Scripting
CVE-2009-4900 2024-11-21 10:10 2019-10-29 Show GitHub Exploit DB Packet Storm
312603 9.8 CRITICAL
Network
pixelpost pixelpost pixelpost 1.7.1 has SQL injection CWE-89
SQL Injection
CVE-2009-4899 2024-11-21 10:10 2019-10-29 Show GitHub Exploit DB Packet Storm
312604 - justsystems just_smile
atok
atok_flat-rate_service
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the sc… NVD-CWE-noinfo
CVE-2009-4738 2024-11-21 10:10 2013-01-19 Show GitHub Exploit DB Packet Storm
312605 - mozilla firefox Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted… CWE-79
Cross-site Scripting
CVE-2009-5017 2024-11-21 10:10 2010-11-13 Show GitHub Exploit DB Packet Storm
312606 - php php Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanism… CWE-189
Numeric Errors
CVE-2009-5016 2024-11-21 10:10 2010-11-13 Show GitHub Exploit DB Packet Storm
312607 - turbogears turbogears2 The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decoration is not used, which has unspecified impact and attack vectors. NVD-CWE-noinfo
CVE-2009-5015 2024-11-21 10:10 2010-11-6 Show GitHub Exploit DB Packet Storm
312608 - turbogears turbogears2 The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authoriz… CWE-310
Cryptographic Issues
CVE-2009-5014 2024-11-21 10:10 2010-11-6 Show GitHub Exploit DB Packet Storm
312609 - g.rodola pyftpdlib Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during… CWE-399
 Resource Management Errors
CVE-2009-5013 2024-11-21 10:10 2010-10-20 Show GitHub Exploit DB Packet Storm
312610 - g.rodola pyftpdlib ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-5012 2024-11-21 10:10 2010-10-20 Show GitHub Exploit DB Packet Storm