Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1081 7.5 重要
Network
アップル tvOS
iOS
watchOS
visionos
iPadOS
アップルのiPadOS等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-28959 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1082 4.6 警告
Physics
アップル iOS
iPadOS
アップルのiPadOS等の複数製品における認可されていない行為者への個人情報の漏えいに関する脆弱性 CWE-359
認可されていないアクターへの個人情報の漏えい
CVE-2026-28963 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1083 4.9 警告
Network
アップル iOS
iPadOS
アップルのiPadOS等の複数製品におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-28967 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1084 4.3 警告
Network
アップル visionos
iOS
iPadOS
アップルのiPadOS等の複数製品におけるレンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限に関する脆弱性 CWE-1021
レンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限
CVE-2026-28971 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1085 6.5 警告
Network
アップル tvOS
iOS
watchOS
visionos
iPadOS
アップルのiPadOS等の複数製品における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-28972 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1086 7.5 重要
Network
- アップルのmacOSにおける複数の脆弱性 CWE-200
CWE-269
CVE-2026-28976 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1087 8.8 重要
Local
- アップルのmacOSにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-28978 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1088 7.5 重要
Network
アップル tvOS
iOS
watchOS
visionos
iPadOS
アップルのiPadOS等の複数製品における型の取り違えに関する脆弱性 CWE-843
型の取り違え
CVE-2026-28983 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1089 6.2 警告
Local
アップル tvOS
iOS
iPadOS
アップルのiPadOS等の複数製品におけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-28985 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
1090 5.5 警告
Local
アップル visionos
iOS
iPadOS
watchOS
アップルのiPadOS等の複数製品におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-28988 2026-05-15 11:04 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311651 - - - Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim - CVE-2024-22034 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311652 - - - The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps CWE-78
OS Command 
CVE-2024-22033 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311653 - - - A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written … CWE-200
Information Exposure
CVE-2024-22032 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311654 - - - A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired doma… CWE-295
Improper Certificate Validation 
CVE-2024-22030 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311655 - - - Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-22029 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311656 - - - : Authentication Bypass Using an Alternate Path or Channel vulnerability in sooskriszta, webforza BuddyPress Better Registration allows : Authentication Bypass.This issue affects BuddyPress Better Re… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2024-49247 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311657 - - - A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalat… CWE-269
 Improper Privilege Management
CVE-2023-32196 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311658 - - - A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. … CWE-269
 Improper Privilege Management
CVE-2023-32194 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311659 - - - A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability t… CWE-80
Basic XSS
CVE-2023-32193 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
311660 - - - A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute arbitrary JavaScrip… CWE-80
Basic XSS
CVE-2023-32192 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm