<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/jvndb/10</id>
  <title>Most recent entries from jvndb</title>
  <updated>2026-10-02T07:10:06.573613+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-036180</id>
    <title>jvndb-2026-036180</title>
    <updated>2026-10-02T11:53:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Sharp Corporation contain a path traversal vulnerability.&lt;a href='https://cwe.mitre.org/data/definitions/22.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) - CVE-2026-78249&lt;/li&gt;&lt;/ul&gt;FUJIFILM Business Innovation Corp. reported this vulnerability to JPCERT/CC to notify users of the solution through JVN. JPCERT/CC coordinated with FUJIFILM Business Innovation Corp. and Sharp Corporation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-036180"/>
    <published>2026-10-02T11:53:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-035987</id>
    <title>jvndb-2026-035987</title>
    <updated>2026-09-30T14:12:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Image Scanner Driver for Linux provided by PFU Limited contains multiple vulnerabilities listed below:&lt;a href='https://cwe.mitre.org/data/definitions/78.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/59.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;OS Command Injection (CWE-78) - CVE-2026-78229&lt;/li&gt;&lt;li&gt;Link Following (CWE-59) - CVE-2026-81310&lt;/li&gt;&lt;/ul&gt;Nir Yehoshua of Cipher Security Labs reported these vulnerabilities to PFU Limited and coordinated. After the coordination was completed, PFU Limited reported the case to JPCERT/CC to notify users of the solution through JVN.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-035987"/>
    <published>2026-09-30T14:12:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000140</id>
    <title>jvndb-2026-000140</title>
    <updated>2026-09-29T15:53:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pgpool-II provided by Pgpool Global Development Group contains multiple vulnerabilities listed below:&lt;a href='https://cwe.mitre.org/data/definitions/787.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/295.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/787.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/121.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/476.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/532.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/303.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Out-of-bounds Write (CWE-787) - CVE-2026-92867&lt;/li&gt;&lt;li&gt;Improper Certificate Validation (CWE-295) - CVE-2026-92868&lt;/li&gt;&lt;li&gt;Out-of-bounds Write (CWE-787) - CVE-2026-92869&lt;/li&gt;&lt;li&gt;Stack-based Buffer Overflow (CWE-121) - CVE-2026-92870&lt;/li&gt;&lt;li&gt;NULL Pointer Dereference (CWE-476) - CVE-2026-92871&lt;/li&gt;&lt;li&gt;Insertion of Sensitive Information into Log File (CWE-532) - CVE-2026-92872&lt;/li&gt;&lt;li&gt;Incorrect Implementation of Authentication Algorithm (CWE-303) - CVE-2026-92873&lt;/li&gt;&lt;/ul&gt;Emond Papegaaij of Topicus Security reported these vulnerabilities to Pgpool Global Development Group and coordinated. Pgpool Global Development Group and JPCERT/CC published respective advisories in order to notify users of this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000140"/>
    <published>2026-09-29T15:53:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-035794</id>
    <title>jvndb-2026-035794</title>
    <updated>2026-09-29T13:35:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The web configuration user interfaces of Wi-Fi products provided by BUFFALO INC. contain multiple vulnerabilities listed below.&lt;a href='https://cwe.mitre.org/data/definitions/78.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/121.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;OS command injection (CWE-78) - CVE-2026-86530&lt;/li&gt;&lt;li&gt;Stack-based buffer overflow (CWE-121) - CVE-2026-95104&lt;/li&gt;&lt;/ul&gt;Veeti Punnonen reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-035794"/>
    <published>2026-09-29T13:35:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-033235</id>
    <title>jvndb-2026-033235</title>
    <updated>2026-09-29T12:18:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&lt;a href='https://cwe.mitre.org/data/definitions/79.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/78.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/548.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/1395.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://www.cve.org/CVERecord?id=CVE-2020-7746' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/434.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/79.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/787.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/352.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/256.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/121.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/522.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/95.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788&lt;/li&gt;&lt;li&gt;OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779&lt;/li&gt;&lt;li&gt;Exposure of information through directory listing (CWE-548…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-033235"/>
    <published>2026-09-14T16:32:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-035789</id>
    <title>jvndb-2026-035789</title>
    <updated>2026-09-28T12:02:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CVE-2026-42976 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-49179 | Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-50472 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-54113 | Remote Procedure Call Denial of Service Vulnerability
CVE-2026-54984 | Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-56174 | Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-59122 | Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-59125 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-59126 | Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2026-59127 | Windows Installer Elevation of Privilege Vulnerability
CVE-2026-59128 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability
CVE-2026-59130 | AMD Zen Information Disclosure Vulnerability
CVE-2026-59131 | AMD Zen Information Disclosure Vulnerability
CVE-2026-59132 | Windows TCP/IP Denial of Service Vulnerability
CVE-2026-59134 | Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-59135 | Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-59136 | Microsoft COM for Windows Information Disclosure Vulnerability
CVE-2026-59137 | Windows Event Logging Service Information Disclosure Vulnerability
CVE-2026-59138 |…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-035789"/>
    <published>2026-09-28T12:02:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000141</id>
    <title>jvndb-2026-000141</title>
    <updated>2026-09-25T14:48:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>baserCMS provided by baserCMS User Community contains multiple vulnerabilities listed below:&lt;a href='https://cwe.mitre.org/data/definitions/79.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/89.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Cross-site scripting (CWE-79) - CVE-2026-93460, CVE-2026-93463, CVE-2026-93464&lt;/li&gt;&lt;li&gt;SQL injection (CWE-89) - CVE-2026-62956&lt;/li&gt;&lt;li&gt;Missing authentication for critical function (CWE-306) - CVE-2026-93462&lt;/li&gt;&lt;/ul&gt;CVE-2026-93460
So Kato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-62956, CVE-2026-93462
Yuji Tounai of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-93463
Gai Tanaka of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-93464
Kuniyoshi Noguchi (KuniNogu) of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000141"/>
    <published>2026-09-25T14:48:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000138</id>
    <title>jvndb-2026-000138</title>
    <updated>2026-09-25T14:48:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>baserCMS plugin "BcAddonMigrator" provided by baserCMS Users Community contains the following vulnerability.&lt;a href='https://cwe.mitre.org/data/definitions/829.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Inclusion of Functionality from Untrusted Control Sphere (CWE-829) - CVE-2026-97150&lt;/li&gt;&lt;/ul&gt;Kuniyoshi Noguchi (KuniNogu) of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000138"/>
    <published>2026-09-25T14:48:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000137</id>
    <title>jvndb-2026-000137</title>
    <updated>2026-09-17T18:06:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Smartphone application Tohoku Electric Power "Yorisou e Net" provided by Tohoku Electric Power Company, Incorporated contains the following vulnerability:&lt;a href='https://cwe.mitre.org/data/definitions/321.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Use of hard-coded cryptographic key (CWE-321) - CVE-2026-75553&lt;/li&gt;&lt;/ul&gt;Yuta Sasaki of Ai Solutions Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000137"/>
    <published>2026-09-17T18:06:00+09:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000135</id>
    <title>jvndb-2026-000135</title>
    <updated>2026-09-16T15:05:00+09:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QND Standard/Premium provided by QualitySoft Corporation contains multiple vulnerabilities listed below:&lt;a href='https://cwe.mitre.org/data/definitions/321.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/782.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Use of hard-coded cryptographic key (CWE-321) - CVE-2026-81326&lt;/li&gt;&lt;li&gt;Improper access control on a named pipe (CWE-782) - CVE-2026-84408&lt;/li&gt;&lt;/ul&gt;Taisei Ogura of MOTEX Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000135"/>
    <published>2026-09-16T15:05:00+09:00</published>
  </entry>
</feed>
