Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1361 9.8 緊急
Network
SolarWinds Web Help Desk SolarWindsのWeb Help Deskにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-40553 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
1362 9.8 緊急
Network
SolarWinds Web Help Desk SolarWindsのWeb Help Deskにおける弱い認証に関する脆弱性 CWE-1390
脆弱な認証
CVE-2025-40554 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
1363 5.5 警告
Local
Pure Storage, Inc. Portworx Pure Storage, Inc.のPortworxにおけるエンコードおよびエスケープに関する脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2025-9127 2026-02-5 15:51 2025-12-4 Show GitHub Exploit DB Packet Storm
1364 6.5 警告
Network
Tildeslash Ltd. M/Monit Tildeslash Ltd.のM/Monitにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2020-36968 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
1365 8.8 重要
Network
Tildeslash Ltd. M/Monit Tildeslash Ltd.のM/Monitにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2020-36969 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
1366 9.8 緊急
Network
Joakim Nygard and Jacob Oettinger Webgrind Webgrind projectのWebgrindにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2023-54339 2026-02-5 15:51 2026-01-13 Show GitHub Exploit DB Packet Storm
1367 6.1 警告
Network
Joakim Nygard and Jacob Oettinger Webgrind Webgrind projectのWebgrindにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2023-54341 2026-02-5 15:51 2026-01-13 Show GitHub Exploit DB Packet Storm
1368 5.4 警告
Network
tagify project tagify FactorialのTagifyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-13983 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
1369 9.8 緊急
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-15115 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
1370 7.5 重要
Network
Redlib Redlib Redlibにおける複数の脆弱性 CWE-400
CWE-502
CVE-2025-30160 2026-02-5 15:50 2025-03-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 6.5 MEDIUM
Network
technitium dnsserver Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation. Update CWE-684
 Incorrect Provision of Specified Functionality
CVE-2026-42255 2026-04-30 03:54 2026-04-26 Show GitHub Exploit DB Packet Storm
2 8.8 HIGH
Network
tenda f456_firmware A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads … Update CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7019 2026-04-30 03:44 2026-04-26 Show GitHub Exploit DB Packet Storm
3 8.8 HIGH
Network
tenda f456_firmware A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can … Update CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7029 2026-04-30 03:36 2026-04-26 Show GitHub Exploit DB Packet Storm
4 8.8 HIGH
Network
tenda f456_firmware A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page leads to buffer over… Update CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7030 2026-04-30 03:36 2026-04-26 Show GitHub Exploit DB Packet Storm
5 8.8 HIGH
Network
tenda f456_firmware A vulnerability was detected in Tenda F456 1.0.0.5. This impacts the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page results in buffer overflow. It… Update CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7031 2026-04-30 03:29 2026-04-26 Show GitHub Exploit DB Packet Storm
6 8.8 HIGH
Network
tenda f456_firmware A flaw has been found in Tenda F456 1.0.0.5. Affected is the function SafeEmailFilter of the file /goform/SafeEmailFilter. This manipulation of the argument page causes buffer overflow. The attack ca… Update CWE-119
CWE-120
Incorrect Access of Indexable Resource ('Range Error') 
Classic Buffer Overflow
CVE-2026-7032 2026-04-30 03:26 2026-04-26 Show GitHub Exploit DB Packet Storm
7 5.9 MEDIUM
Network
vmware spring_ai In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conv… New CWE-284
Improper Access Control
CVE-2026-40966 2026-04-30 03:18 2026-04-28 Show GitHub Exploit DB Packet Storm
8 8.8 HIGH
Network
vmware spring_ai SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0… New CWE-89
SQL Injection
CVE-2026-40978 2026-04-30 03:16 2026-04-28 Show GitHub Exploit DB Packet Storm
9 6.1 MEDIUM
Local
vmware spring_ai In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) New CWE-377
 Insecure Temporary File
CVE-2026-40979 2026-04-30 03:16 2026-04-28 Show GitHub Exploit DB Packet Storm
10 5.3 MEDIUM
Network
- - A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Ad… New CWE-22
Path Traversal
CVE-2026-7396 2026-04-30 03:16 2026-04-30 Show GitHub Exploit DB Packet Storm