Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1421 5.3 警告
Network
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-35061 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
1422 9.8 緊急
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35546 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
1423 8.8 重要
Network
Anviz Global Anviz CX2 Lite Firmware Anviz GlobalのAnviz CX2 Lite Firmwareにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-35682 2026-05-7 11:29 2026-04-17 Show GitHub Exploit DB Packet Storm
1424 7.5 重要
Network
Belkin International N300 firmware U-SpeedのN300 Firmwareにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-36958 2026-05-7 11:29 2026-04-30 Show GitHub Exploit DB Packet Storm
1425 7.5 重要
Network
Belkin International N300 firmware U-SpeedのN300 Firmwareにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2026-36959 2026-05-7 11:29 2026-04-30 Show GitHub Exploit DB Packet Storm
1426 8.8 重要
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品におけるダウンロードしたコードの完全性検証不備に関する脆弱性 CWE-494
ダウンロードしたコードの完全性検証不備
CVE-2026-40066 2026-05-7 11:29 2026-04-17 Show GitHub Exploit DB Packet Storm
1427 8.1 重要
Adjacent
Anviz Global Crosschex Standard Anviz GlobalのCrosschex Standardにおける通信チャネルの送信元の不適切な検証に関する脆弱性 CWE-940
通信チャネルの送信元の不適切な検証
CVE-2026-40434 2026-05-7 11:29 2026-04-17 Show GitHub Exploit DB Packet Storm
1428 7.5 重要
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-40461 2026-05-7 11:29 2026-04-17 Show GitHub Exploit DB Packet Storm
1429 5.3 警告
Network
asrmicro ASR1901 Firmware
ASR1903 Firmware
asrmicroのASR1901 Firmware等の複数製品におけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-42800 2026-05-7 11:29 2026-04-30 Show GitHub Exploit DB Packet Storm
1430 7.5 重要
Network
OpenStack Ironic Python Agent OpenStackのIronic Python Agentにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-43003 2026-05-7 11:29 2026-05-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312831 8.8 HIGH
Network
qnap qts
quts_hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a … CWE-120
CWE-121
Classic Buffer Overflow
Stack-based Buffer Overflow
CVE-2023-51367 2024-09-11 22:27 2024-09-7 Show GitHub Exploit DB Packet Storm
312832 6.5 MEDIUM
Network
zoom workplace
workplace_desktop
workplace_virtual_desktop_infrastructure
rooms
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access. CWE-522
 Insufficiently Protected Credentials
CVE-2024-39818 2024-09-11 22:27 2024-08-15 Show GitHub Exploit DB Packet Storm
312833 6.5 MEDIUM
Network
terminalfour terminalfour A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-22217 2024-09-11 22:19 2024-08-16 Show GitHub Exploit DB Packet Storm
312834 5.4 MEDIUM
Network
yogeshojha rengine reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a… CWE-79
Cross-site Scripting
CVE-2024-43381 2024-09-11 22:02 2024-08-17 Show GitHub Exploit DB Packet Storm
312835 9.8 CRITICAL
Network
h3c magic_b1st_firmware H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. CWE-798
 Use of Hard-coded Credentials
CVE-2024-42638 2024-09-11 21:53 2024-08-17 Show GitHub Exploit DB Packet Storm
312836 7.5 HIGH
Network
google android In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution pri… CWE-120
Classic Buffer Overflow
CVE-2024-34727 2024-09-11 21:43 2024-08-16 Show GitHub Exploit DB Packet Storm
312837 8.2 HIGH
Network
xpdfreader xpdf In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read fro… CWE-908
 Use of Uninitialized Resource
CVE-2024-7868 2024-09-11 21:40 2024-08-16 Show GitHub Exploit DB Packet Storm
312838 8.8 HIGH
Network
xyzscripts insert_php_code_snippet Cross-Site Request Forgery (CSRF) vulnerability in xyzscripts.Com Insert PHP Code Snippet.This issue affects Insert PHP Code Snippet: from n/a through 1.3.6. CWE-352
 Origin Validation Error
CVE-2024-43275 2024-09-11 21:33 2024-08-15 Show GitHub Exploit DB Packet Storm
312839 - - - Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Comm… - CVE-2024-43690 2024-09-11 14:15 2024-09-11 Show GitHub Exploit DB Packet Storm
312840 - - - Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious … - CVE-2024-21529 2024-09-11 14:15 2024-09-11 Show GitHub Exploit DB Packet Storm