Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1341 7.5 重要
Network
The Tor Project Tor The Tor ProjectのTorにおける単一、固有のアクションの実施に関する脆弱性 CWE-837
単一、固有のアクションの不適切な実施
CVE-2026-44601 2026-05-11 11:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1342 7.5 重要
Network
The Tor Project Tor The Tor ProjectのTorにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-44602 2026-05-11 11:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1343 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-125
CVE-2026-8084 2026-05-11 11:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1344 7.8 重要
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CVE-2026-8086 2026-05-11 11:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1345 7.8 重要
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CVE-2026-8087 2026-05-11 11:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1346 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-125
CVE-2026-8088 2026-05-11 11:03 2026-05-7 Show GitHub Exploit DB Packet Storm
1347 7.3 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-8090 2026-05-11 11:03 2026-05-7 Show GitHub Exploit DB Packet Storm
1348 7.8 重要
Local
Forcepoint LLC. Next Generation Firewall (NGFW) Forcepoint LLC.のNext Generation Firewall (NGFW)における不要な特権による実行に関する脆弱性 CWE-250
CWE-noinfo
CVE-2025-12690 2026-05-11 11:03 2026-03-11 Show GitHub Exploit DB Packet Storm
1349 6.8 警告
Network
vaadin Vaadin Vaadin Ltd.のVaadinにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-2741 2026-05-11 11:03 2026-03-10 Show GitHub Exploit DB Packet Storm
1350 5.3 警告
Network
vaadin Vaadin Vaadin Ltd.のVaadinにおけるアクセス制御に関する脆弱性 CWE-284
CWE-Other
CVE-2026-2742 2026-05-11 11:03 2026-03-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312351 6.5 MEDIUM
Network
jakesnyder enhanced_search_box The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack CWE-352
 Origin Validation Error
CVE-2024-8091 2024-09-28 03:17 2024-09-17 Show GitHub Exploit DB Packet Storm
312352 4.3 MEDIUM
Network
github enterprise_server An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was … CWE-863
 Incorrect Authorization
CVE-2024-7711 2024-09-28 03:17 2024-08-21 Show GitHub Exploit DB Packet Storm
312353 6.5 MEDIUM
Network
lucasgarcia posts_reminder The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack CWE-352
 Origin Validation Error
CVE-2024-8093 2024-09-28 03:16 2024-09-17 Show GitHub Exploit DB Packet Storm
312354 6.5 MEDIUM
Network
elliot ilc_thickbox The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack CWE-352
 Origin Validation Error
CVE-2024-7820 2024-09-28 03:08 2024-09-12 Show GitHub Exploit DB Packet Storm
312355 9.1 CRITICAL
Network
matter-labs zkvyper zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit conditio… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-43366 2024-09-28 03:08 2024-08-16 Show GitHub Exploit DB Packet Storm
312356 6.1 MEDIUM
Network
gwycon quick_code The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XS… CWE-79
Cross-site Scripting
CVE-2024-7822 2024-09-28 03:06 2024-09-12 Show GitHub Exploit DB Packet Storm
312357 6.5 MEDIUM
Network
visual_sound_project visual_sound The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack CWE-352
 Origin Validation Error
CVE-2024-7859 2024-09-28 03:00 2024-09-12 Show GitHub Exploit DB Packet Storm
312358 8.8 HIGH
Network
dedebiz dedebiz A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/select_images_post.php of the component Attachment S… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7906 2024-09-28 02:54 2024-08-18 Show GitHub Exploit DB Packet Storm
312359 6.5 MEDIUM
Network
github enterprise_server An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content i… CWE-863
 Incorrect Authorization
CVE-2024-6337 2024-09-28 02:48 2024-08-21 Show GitHub Exploit DB Packet Storm
312360 5.4 MEDIUM
Network
kirstyburgoine responsive_video The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings function in all versions up to, and including, 1.0 due to insufficient input san… CWE-79
Cross-site Scripting
CVE-2024-7629 2024-09-28 02:32 2024-08-21 Show GitHub Exploit DB Packet Storm