= Japan Vulnerability Notes =

Japan Vulnerability Notes
- Type: Vulnerability countermeasure information portal
- Language: Japanese, English
- Owner: Japan Computer Emergency Response Team Coordination Center and Information-technology Promotion Agency (IPA)
- Area Served: Japan
- Url: jvn.jp
- Commercial: No
- Current Status: Online

Japan Vulnerability Notes (JVN) is Japan's national vulnerability database and security advisory portal for software products used in Japan. It publishes information about security vulnerabilities, vendor responses and mitigation measures, and is jointly operated by the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) and the Japanese government's Information-technology Promotion Agency.

==History==
JPCERT/CC and IPA have coordinated the handling of software vulnerabilities in Japan since 2004 under the Information Security Early Warning Partnership, a national framework for early disclosure of vulnerabilities. JVN was developed as a public portal to publish vulnerability countermeasure information collected through this framework for software products used in Japan.

In April 2007, IPA launched the companion database JVN iPedia as a public archive of vulnerability countermeasure information derived from JVN and other sources, and during its first six months the Japanese-language version catalogued about 4,100 vulnerabilities. By 2012, JVN had adopted the Security Content Automation Protocol (SCAP) to standardise its vulnerability data for automated processing.

==Functions and structure==
Under the Information Security Early Warning Partnership, IPA receives privately reported vulnerabilities affecting software used in Japan and JPCERT/CC coordinates with software developers to prepare patches or other countermeasures, which are then published via JVN. JVN entries include a description of the vulnerability, analysis by JPCERT/CC, vendor notes and recommended solutions, and may also provide chronological status tracking notes on exploit code, incidents and the availability of fixes. JVN offers updates in RSS format and tools that allow organisations to display recent advisories on their own websites.

The Forum of Incident Response and Security Teams (FIRST) describes JVN as a vulnerability-handling coordination database that provides vulnerability countermeasure information and Japanese vendor status for vulnerabilities reported through the Information Security Early Warning Partnership, using identifiers of the form JVN#NNNNNNNN and JVNVU#NNNNNNNN. The associated database JVN iPedia, maintained by IPA, stores summary and countermeasure information for vulnerabilities published on JVN and other sources and assigns identifiers of the form JVNDB-YYYY-NNNNNN. JVN iPedia supports keyword and product search, CVSS severity scores and CPE product identifiers, and can be queried using CVE identifiers.

JVN and JVN iPedia together function as Japan's national vulnerability database within the global CVE ecosystem. The CVE Foundation notes that JVN ingests CVE entries, enriches them with local context and JVN-specific identifiers and has participated as a CVE data source since 2008. According to IPA, JVN iPedia stored 208,034 vulnerability records as of the second quarter of 2024, rising to 242,898 by the second quarter of 2025.
