Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
101 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける領域間での誤ったリソース移動に関する脆弱性 New CWE-669
領域間での誤ったリソース移動
CVE-2026-31431 2026-05-7 12:06 2026-04-22 Show GitHub Exploit DB Packet Storm
102 5.3 警告
Network
レッドハット
kernel.org
util-linux
Red Hat Hardened Images
kernel.org等の複数ベンダの製品における代替名による認証回避に関する脆弱性 New CWE-289
代替名による認証回避
CVE-2026-3184 2026-05-7 12:06 2026-04-3 Show GitHub Exploit DB Packet Storm
103 5.5 警告
Local
Electron electron Electronのelectronにおける解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-34764 2026-05-7 12:06 2026-04-6 Show GitHub Exploit DB Packet Storm
104 10 緊急
Network
traefik traefik traefikにおけるデータの信頼性についての不十分な検証に関する脆弱性 New CWE-345
データの信頼性についての不十分な検証
CVE-2026-35051 2026-05-7 12:06 2026-04-30 Show GitHub Exploit DB Packet Storm
105 7.1 重要
Network
デル iDRAC10 Firmware デルのiDRAC10 Firmwareにおける認証情報の不十分な保護に関する脆弱性 New CWE-522
認証情報の不十分な保護
CVE-2026-35155 2026-05-7 12:06 2026-04-29 Show GitHub Exploit DB Packet Storm
106 7.2 重要
Network
Progress Software Corporation ECS Connection Manager
loadmaster
Connection Manager for ObjectScale
Progress Software CorporationのConnection Manager for ObjectScale等の複数製品におけるコマンドインジェクションの脆弱性 New CWE-77
コマンドインジェクション
CVE-2026-3517 2026-05-7 12:06 2026-04-20 Show GitHub Exploit DB Packet Storm
107 7.2 重要
Network
Progress Software Corporation ECS Connection Manager
loadmaster
Connection Manager for ObjectScale
Progress Software CorporationのConnection Manager for ObjectScale等の複数製品におけるコマンドインジェクションの脆弱性 New CWE-77
コマンドインジェクション
CVE-2026-3518 2026-05-7 12:06 2026-04-20 Show GitHub Exploit DB Packet Storm
108 7.2 重要
Network
Progress Software Corporation ECS Connection Manager
loadmaster
Connection Manager for ObjectScale
Progress Software CorporationのConnection Manager for ObjectScale等の複数製品におけるコマンドインジェクションの脆弱性 New CWE-77
コマンドインジェクション
CVE-2026-3519 2026-05-7 12:06 2026-04-20 Show GitHub Exploit DB Packet Storm
109 8.1 重要
Network
FreeBSD FreeBSD FreeBSDにおける複数の脆弱性 New CWE-122
CWE-130
CVE-2026-35547 2026-05-7 12:06 2026-04-30 Show GitHub Exploit DB Packet Storm
110 7.5 重要
Network
libsndfile project libsndfile libsndfile projectのlibsndfileにおける整数オーバーフローの脆弱性 New CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-37555 2026-05-7 12:06 2026-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312801 - - - Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution. - CVE-2024-23168 2024-08-19 22:00 2024-08-16 Show GitHub Exploit DB Packet Storm
312802 - - - XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which cou… - CVE-2024-22218 2024-08-19 22:00 2024-08-16 Show GitHub Exploit DB Packet Storm
312803 - - - Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users accoun… - CVE-2024-25582 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312804 - - - Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-43350 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312805 - - - Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100. - CVE-2024-43322 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312806 - - - Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-43315 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312807 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Timeline Lite allows Stored XSS.This issue affects Bold Timeline Lite: fro… CWE-79
Cross-site Scripting
CVE-2024-43294 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312808 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This iss… CWE-79
Cross-site Scripting
CVE-2024-43292 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312809 - - - Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-43288 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm
312810 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a throu… CWE-89
SQL Injection
CVE-2024-43286 2024-08-19 21:59 2024-08-19 Show GitHub Exploit DB Packet Storm