Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
91 9.6 緊急
Network
langflow langflow langflowにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-42048 2026-05-15 11:00 2026-05-12 Show GitHub Exploit DB Packet Storm
92 5.5 警告
Local
ImageMagick ImageMagick ImageMagickにおけるスタックベースのバッファオーバーフローの脆弱性 New CWE-121
スタックオーバーフロー
CVE-2026-42050 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
93 8.1 重要
Network
- OpenC3のOpenC3 COSMOSにおける不要な特権による実行に関する脆弱性 New CWE-250
不要な特権による実行
CVE-2026-42088 2026-05-15 11:00 2026-05-4 Show GitHub Exploit DB Packet Storm
94 8.8 重要
Network
litellm litellm LiteLLMにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 New CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-42203 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
95 9.1 緊急
Network
axios project axios axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 New CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42264 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
96 5.7 警告
Network
Kimai project kimai Kimai projectのKimaiにおけるCSV ファイル内の数式要素の中和に関する脆弱性 New CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2026-42267 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
97 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおける不特定の脆弱性 New CWE-noinfo
情報不足
CVE-2026-42499 2026-05-15 11:00 2026-05-7 Show GitHub Exploit DB Packet Storm
98 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおけるデジタル署名の検証に関する脆弱性 New CWE-347
デジタル署名の不適切な検証
CVE-2026-42501 2026-05-15 11:00 2026-05-7 Show GitHub Exploit DB Packet Storm
99 9.1 緊急
Network
Grav CMS grav Grav CMSのgravにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-42608 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
100 5.4 警告
Network
Open edX openedx Open edXのopenedxにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42857 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311991 9.8 CRITICAL
Network
rockwellautomation factorytalk_batch_view CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impers… NVD-CWE-noinfo
CVE-2024-45823 2024-10-2 23:49 2024-09-13 Show GitHub Exploit DB Packet Storm
311992 8.3 HIGH
Network
nvidia nvidia_container_toolkit
nvidia_gpu_operator
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain acces… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-0132 2024-10-2 23:45 2024-09-26 Show GitHub Exploit DB Packet Storm
311993 3.4 LOW
Network
nvidia nvidia_container_toolkit
nvidia_gpu_operator
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This d… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-0133 2024-10-2 23:43 2024-09-26 Show GitHub Exploit DB Packet Storm
311994 7.5 HIGH
Network
rockwellautomation 5015-u8ihft_firmware CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a m… NVD-CWE-noinfo
CVE-2024-45825 2024-10-2 23:43 2024-09-13 Show GitHub Exploit DB Packet Storm
311995 8.8 HIGH
Network
rockwellautomation thinmanager CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If exploited, a user ca… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2024-45826 2024-10-2 23:35 2024-09-13 Show GitHub Exploit DB Packet Storm
311996 7.5 HIGH
Network
clibomanager clibo_manager Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of servi… NVD-CWE-Other
CVE-2024-9199 2024-10-2 23:33 2024-09-26 Show GitHub Exploit DB Packet Storm
311997 5.4 MEDIUM
Network
clibomanager clibo_manager Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile pict… CWE-79
Cross-site Scripting
CVE-2024-9198 2024-10-2 23:33 2024-09-26 Show GitHub Exploit DB Packet Storm
311998 4.8 MEDIUM
Network
radiustheme the_post_grid The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scrip… CWE-79
Cross-site Scripting
CVE-2024-3635 2024-10-2 23:30 2024-09-30 Show GitHub Exploit DB Packet Storm
311999 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Require drivers to supply the cache_invalidate_user ops If drivers don't do this then iommufd will oops invalidation ioc… CWE-476
 NULL Pointer Dereference
CVE-2024-46824 2024-10-2 23:29 2024-09-27 Show GitHub Exploit DB Packet Storm
312000 8.1 HIGH
Network
acquia mautic Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the Mautic user had, they could delete fil… CWE-22
Path Traversal
CVE-2021-27916 2024-10-2 23:29 2024-09-18 Show GitHub Exploit DB Packet Storm