Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1011 9.1 緊急
Network
Technostrobe HI-LED-WR120-G2 Firmware TechnostrobeのHI-LED-WR120-G2 Firmwareにおける複数の脆弱性 CWE-862
CWE-863
CVE-2026-5574 2026-05-7 12:00 2026-04-5 Show GitHub Exploit DB Packet Storm
1012 7.1 重要
Local
レッドハット
Xiph.Org
Red Hat Enterprise Linux
Theora
レッドハット等の複数ベンダの製品における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-5673 2026-05-7 12:00 2026-04-6 Show GitHub Exploit DB Packet Storm
1013 9.8 緊急
Network
Sipeed Picoclaw SipeedのPicoclawにおける複数の脆弱性 CWE-74
CWE-77
CVE-2026-6987 2026-05-7 12:00 2026-04-25 Show GitHub Exploit DB Packet Storm
1014 8.8 重要
Network
Coze Coze Studio CozeのCoze Studioにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-7023 2026-05-7 12:00 2026-04-26 Show GitHub Exploit DB Packet Storm
1015 7.3 重要
Network
ShadowCloneLabs Glutamate MCP Servers ShadowCloneLabsのGlutamate MCP Serversにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-7094 2026-05-7 12:00 2026-04-27 Show GitHub Exploit DB Packet Storm
1016 5.4 警告
Network
helpy.io helpy helpy.ioのhelpyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40229 2026-05-7 12:00 2026-04-29 Show GitHub Exploit DB Packet Storm
1017 5.4 警告
Network
helpy.io helpy helpy.ioのhelpyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40230 2026-05-7 12:00 2026-04-29 Show GitHub Exploit DB Packet Storm
1018 7.5 重要
Network
Exim Development Exim Exim DevelopmentのEximにおける指定された機能の不適切な提供に関する脆弱性 CWE-684
指定された機能の不適切な提供
CVE-2026-40684 2026-05-7 12:00 2026-04-30 Show GitHub Exploit DB Packet Storm
1019 9.8 緊急
Network
Exim Development Exim Exim DevelopmentのEximにおける複数の脆弱性 CWE-684
CWE-787
CVE-2026-40685 2026-05-7 12:00 2026-04-30 Show GitHub Exploit DB Packet Storm
1020 5.3 警告
Network
Exim Development Exim Exim DevelopmentのEximにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-40686 2026-05-7 12:00 2026-04-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312601 7.8 HIGH
Local
intel license_manager_for_flexim Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local… CWE-427
 Uncontrolled Search Path Element
CVE-2024-24977 2024-09-13 03:45 2024-08-14 Show GitHub Exploit DB Packet Storm
312602 7.8 HIGH
Local
intel flexlm_license_daemons_for_intel_fpga Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via lo… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-23908 2024-09-13 03:43 2024-08-14 Show GitHub Exploit DB Packet Storm
312603 9.8 CRITICAL
Network
openedx openedx This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repos… CWE-74
Injection
CVE-2024-43782 2024-09-13 03:29 2024-08-24 Show GitHub Exploit DB Packet Storm
312604 7.8 HIGH
Local
steveklabnik request_store RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to … CWE-276
Incorrect Default Permissions 
CVE-2024-43791 2024-09-13 03:26 2024-08-24 Show GitHub Exploit DB Packet Storm
312605 8.8 HIGH
Local
intel ethernet_800_series_controllers_driver Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of pri… CWE-787
 Out-of-bounds Write
CVE-2024-23497 2024-09-13 03:26 2024-08-14 Show GitHub Exploit DB Packet Storm
312606 6.1 MEDIUM
Network
jeesite jeesite A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulati… CWE-79
Cross-site Scripting
CVE-2024-8112 2024-09-13 03:23 2024-08-24 Show GitHub Exploit DB Packet Storm
312607 5.4 MEDIUM
Network
pretix pretix Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of… CWE-79
Cross-site Scripting
CVE-2024-8113 2024-09-13 03:21 2024-08-24 Show GitHub Exploit DB Packet Storm
312608 6.5 MEDIUM
Network
gethomepage homepage Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and auth… CWE-290
 Authentication Bypass by Spoofing
CVE-2024-42364 2024-09-13 03:20 2024-08-24 Show GitHub Exploit DB Packet Storm
312609 - - - In the Linux kernel, the following vulnerability has been resolved: nfs: pass explicit offset/count to trace events nfs_folio_length is unsafe to use without having the folio locked and a check for… - CVE-2024-43826 2024-09-13 03:15 2024-08-17 Show GitHub Exploit DB Packet Storm
312610 7.3 HIGH
Local
intel virtual_raid_on_cpu Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2024-23489 2024-09-13 03:11 2024-08-14 Show GitHub Exploit DB Packet Storm