Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1191 7.5 重要
Network
axios project axios axios projectのaxiosにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-42038 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1192 7.5 重要
Network
axios project axios axios projectのaxiosにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-42039 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1193 3.7
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-116
CWE-626
CVE-2026-42040 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1194 6.5 警告
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-1321
CWE-287
CVE-2026-42041 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1195 5.4 警告
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-183
CWE-201
CVE-2026-42042 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1196 10 緊急
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-183
CWE-441
CWE-918
CVE-2026-42043 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1197 9.1 緊急
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-1321
CWE-915
CVE-2026-42044 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
1198 8.8 重要
Network
HashiCorp Vault HashiCorpのVaultにおける送信データへの重要な情報の挿入に関する脆弱性 CWE-201
送信データへの重要な情報の挿入
CVE-2026-4525 2026-04-30 12:25 2026-04-17 Show GitHub Exploit DB Packet Storm
1199 4.9 警告
Network
IBM IBM Guardium Data Protection IBMのIBM Guardium Data Protectionにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-4917 2026-04-30 12:25 2026-04-23 Show GitHub Exploit DB Packet Storm
1200 4.8 警告
Network
IBM IBM Guardium Data Protection IBMのIBM Guardium Data Protectionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4918 2026-04-30 12:25 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313161 8.8 HIGH
Network
ivanti endpoint_manager_mobile An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the ap… CWE-502
 Deserialization of Untrusted Data
CVE-2024-36131 2024-08-22 03:35 2024-08-7 Show GitHub Exploit DB Packet Storm
313162 9.6 CRITICAL
Network
koha koha Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component. CWE-79
Cross-site Scripting
CVE-2024-28740 2024-08-22 03:35 2024-08-7 Show GitHub Exploit DB Packet Storm
313163 - - - Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions before 1.979. A physically close attacker that is authenticated to the Blueto… - CVE-2024-40893 2024-08-22 03:15 2024-08-13 Show GitHub Exploit DB Packet Storm
313164 - - - A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for authentication and provision … - CVE-2024-40892 2024-08-22 03:15 2024-08-13 Show GitHub Exploit DB Packet Storm
313165 7.5 HIGH
Network
tenda fh1201_firmware Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (Do… CWE-787
 Out-of-bounds Write
CVE-2024-42950 2024-08-22 02:35 2024-08-16 Show GitHub Exploit DB Packet Storm
313166 - - - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gai… - CVE-2024-43411 2024-08-22 02:25 2024-08-22 Show GitHub Exploit DB Packet Storm
313167 - - - Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH packet consists of a 4-byte big-endian length, foll… - CVE-2024-43410 2024-08-22 02:25 2024-08-22 Show GitHub Exploit DB Packet Storm
313168 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affect… - CVE-2022-26328 2024-08-22 02:25 2024-08-22 Show GitHub Exploit DB Packet Storm
313169 - - - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63. - CVE-2022-26327 2024-08-22 02:25 2024-08-22 Show GitHub Exploit DB Packet Storm
313170 - - - Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authenticatio… CWE-89
SQL Injection
CVE-2024-5723 2024-08-22 02:24 2024-08-22 Show GitHub Exploit DB Packet Storm