Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1281 7 重要
Local
Vim Vim Vimにおける複数の脆弱性 CWE-78
CWE-88
CVE-2026-46483 2026-05-21 10:50 2026-05-15 Show GitHub Exploit DB Packet Storm
1282 7.3 重要
Network
Apache Software Foundation Apache OFBiz Apache Software FoundationのApache OFBizにおける複数の脆弱性 CWE-94
CWE-95
CVE-2026-46586 2026-05-21 10:50 2026-05-19 Show GitHub Exploit DB Packet Storm
1283 5 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-6333 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1284 6.5 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-6340 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1285 9.8 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-7301 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1286 9.1 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおけるパストラバーサルの脆弱性 CWE-35
パストラバーサル
CVE-2026-7302 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1287 9.8 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-7304 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1288 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CWE-125
CVE-2026-8212 2026-05-21 10:49 2026-05-9 Show GitHub Exploit DB Packet Storm
1289 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CWE-125
CVE-2026-8213 2026-05-21 10:49 2026-05-9 Show GitHub Exploit DB Packet Storm
1290 7.5 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける不変と仮定される Web パラメータの外部制御に関する脆弱性 CWE-472
不変と仮定される Web パラメータの外部制御
CVE-2026-8510 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319251 4.3 MEDIUM
Network
smashballoon reviews_feed The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… CWE-862
 Missing Authorization
CVE-2024-8199 2024-08-31 00:04 2024-08-28 Show GitHub Exploit DB Packet Storm
319252 8.8 HIGH
Network
skyss arfa-cms A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges. CWE-352
 Origin Validation Error
CVE-2024-45264 2024-08-31 00:02 2024-08-28 Show GitHub Exploit DB Packet Storm
319253 9.8 CRITICAL
Network
dlink dir-846w_firmware D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request. CWE-78
OS Command 
CVE-2024-44342 2024-08-30 23:57 2024-08-28 Show GitHub Exploit DB Packet Storm
319254 9.8 CRITICAL
Network
dlink dir-846w_firmware D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST requ… CWE-78
OS Command 
CVE-2024-44341 2024-08-30 23:57 2024-08-28 Show GitHub Exploit DB Packet Storm
319255 8.8 HIGH
Network
dlink dir-846w_firmware D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings. CWE-78
OS Command 
CVE-2024-44340 2024-08-30 23:56 2024-08-28 Show GitHub Exploit DB Packet Storm
319256 9.8 CRITICAL
Network
dlink dir-846w_firmware D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface. CWE-78
OS Command 
CVE-2024-41622 2024-08-30 23:55 2024-08-28 Show GitHub Exploit DB Packet Storm
319257 6.5 MEDIUM
Network
ptc thingworx An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-40395 2024-08-30 23:35 2024-08-28 Show GitHub Exploit DB Packet Storm
319258 - - - A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet… CWE-94
Code Injection
CVE-2024-5651 2024-08-30 23:15 2024-08-12 Show GitHub Exploit DB Packet Storm
319259 6.5 MEDIUM
Network
gitlab gitlab An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commi… CWE-1333
 Inefficient Regular Expression Complexity
CVE-2024-3114 2024-08-30 23:15 2024-08-8 Show GitHub Exploit DB Packet Storm
319260 9.8 CRITICAL
Network
fortra filecatalyst_workflow The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confi… CWE-798
 Use of Hard-coded Credentials
CVE-2024-6633 2024-08-30 23:11 2024-08-28 Show GitHub Exploit DB Packet Storm