Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1381 6.1 警告
Network
Frappe Press FrappeのPressにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41430 2026-05-1 10:38 2026-04-24 Show GitHub Exploit DB Packet Storm
1382 8.8 重要
Network
D-Link Systems, Inc. DHP-1320 Firmware D-Link CorporationのDHP-1320 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-4529 2026-05-1 10:38 2026-03-21 Show GitHub Exploit DB Packet Storm
1383 7 重要
Local
flos-freeware (Florian Balmer) Notepad2 flos-freeware (Florian Balmer)のNotepad2における複数の脆弱性 CWE-426
CWE-427
CVE-2026-4545 2026-05-1 10:38 2026-03-22 Show GitHub Exploit DB Packet Storm
1384 7 重要
Local
flos-freeware (Florian Balmer) Notepad2 flos-freeware (Florian Balmer)のNotepad2における複数の脆弱性 CWE-426
CWE-427
CVE-2026-4546 2026-05-1 10:38 2026-03-22 Show GitHub Exploit DB Packet Storm
1385 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. 4G03 Pro Firmware Shenzhen Tenda Technology Co.,Ltd.の4G03 Pro Firmwareにおける複数の脆弱性 CWE-266
CWE-284
CVE-2026-5526 2026-05-1 10:38 2026-04-4 Show GitHub Exploit DB Packet Storm
1386 5.3 警告
Network
Shenzhen Tenda Technology Co.,Ltd. 4G03 Pro Firmware Shenzhen Tenda Technology Co.,Ltd.の4G03 Pro Firmwareにおける複数の脆弱性 CWE-320
CWE-321
CVE-2026-5527 2026-05-1 10:38 2026-04-5 Show GitHub Exploit DB Packet Storm
1387 8 重要
Adjacent
Shenzhen Tenda Technology Co.,Ltd. CX12L Pro Firmware Shenzhen Tenda Technology Co.,Ltd.のCX12L Pro Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-5683 2026-05-1 10:38 2026-04-6 Show GitHub Exploit DB Packet Storm
1388 8 重要
Adjacent
Shenzhen Tenda Technology Co.,Ltd. CX12L Pro Firmware Shenzhen Tenda Technology Co.,Ltd.のCX12L Pro Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-5684 2026-05-1 10:38 2026-04-6 Show GitHub Exploit DB Packet Storm
1389 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. CX12L Pro Firmware Shenzhen Tenda Technology Co.,Ltd.のCX12L Pro Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-5685 2026-05-1 10:38 2026-04-6 Show GitHub Exploit DB Packet Storm
1390 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. CX12L Pro Firmware Shenzhen Tenda Technology Co.,Ltd.のCX12L Pro Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-5686 2026-05-1 10:38 2026-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313081 8.1 HIGH
Network
fiware keyrock Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link. CWE-326
Inadequate Encryption Strength
CVE-2024-42163 2024-08-30 00:17 2024-08-12 Show GitHub Exploit DB Packet Storm
313082 9.8 CRITICAL
Network
oretnom23 music_gallery_site A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation of the argu… CWE-89
SQL Injection
CVE-2024-8222 2024-08-30 00:13 2024-08-28 Show GitHub Exploit DB Packet Storm
313083 9.8 CRITICAL
Network
oretnom23 music_gallery_site A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=delete_category. The manipulation … CWE-89
SQL Injection
CVE-2024-8223 2024-08-30 00:11 2024-08-28 Show GitHub Exploit DB Packet Storm
313084 9.8 CRITICAL
Network
angeljudesuarez tailoring_management_system A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file staffedit.php. The … CWE-89
SQL Injection
CVE-2024-8220 2024-08-29 23:49 2024-08-28 Show GitHub Exploit DB Packet Storm
313085 9.0 CRITICAL
Network
microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CWE-843
Type Confusion
CVE-2024-38219 2024-08-29 23:45 2024-08-12 Show GitHub Exploit DB Packet Storm
313086 5.4 MEDIUM
Network
ibm aspera_shares IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574. CWE-384
 Session Fixation
CVE-2023-38018 2024-08-29 23:36 2024-08-12 Show GitHub Exploit DB Packet Storm
313087 7.2 HIGH
Network
abinitio authorization_gateway
metadata_hub
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration. CWE-94
Code Injection
CVE-2024-37382 2024-08-29 23:29 2024-08-9 Show GitHub Exploit DB Packet Storm
313088 5.3 MEDIUM
Network
dorsettcontrols infoscan Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login. NVD-CWE-noinfo
CVE-2024-42493 2024-08-29 23:24 2024-08-9 Show GitHub Exploit DB Packet Storm
313089 7.5 HIGH
Network
dorsettcontrols infoscan Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys. NVD-CWE-noinfo
CVE-2024-39287 2024-08-29 23:23 2024-08-9 Show GitHub Exploit DB Packet Storm
313090 3.7 LOW
Network
dorsettcontrols infoscan The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure. CWE-22
Path Traversal
CVE-2024-42408 2024-08-29 23:22 2024-08-9 Show GitHub Exploit DB Packet Storm