Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
141 6.5 警告
Network
FreeBSD FreeBSD FreeBSDにおける権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-45254 2026-05-25 10:19 2026-05-21 Show GitHub Exploit DB Packet Storm
142 7.5 重要
Adjacent
FreeBSD FreeBSD FreeBSDにおけるOS コマンドインジェクションの脆弱性 New CWE-78
OSコマンド・インジェクション
CVE-2026-45255 2026-05-25 10:19 2026-05-21 Show GitHub Exploit DB Packet Storm
143 3.5
Network
GitHub cli GitHubのcliにおけるエスケープ、メタ、またはコントロールシーケンスの不適切な無効化に関する脆弱性 New CWE-150
エスケープ、メタ、またはコントロールシーケンスの不適切な無効化
CVE-2026-45803 2026-05-25 10:19 2026-05-15 Show GitHub Exploit DB Packet Storm
144 8.1 重要
Network
Memcached Memcached Memcachedにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 New CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-47783 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
145 8.1 重要
Network
Memcached Memcached Memcachedにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 New CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-47784 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
146 9.9 緊急
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-4858 2026-05-25 10:19 2026-05-21 Show GitHub Exploit DB Packet Storm
147 5.5 警告
Local
WebAssembly Binaryen WebAssemblyのBinaryenにおける到達可能なアサーションに関する脆弱性 New CWE-617
到達可能なアサーション
CVE-2026-8257 2026-05-25 10:19 2026-05-11 Show GitHub Exploit DB Packet Storm
148 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-8486 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
149 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける不適切なデフォルトパーミッションに関する脆弱性 New CWE-276
不適切なデフォルトパーミッション
CVE-2026-8487 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
150 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-8488 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311501 4.7 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to read and compare the cursor buffe… NVD-CWE-noinfo
CVE-2024-46710 2024-10-17 23:15 2024-09-13 Show GitHub Exploit DB Packet Storm
311502 4.4 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is… CWE-276
Incorrect Default Permissions 
CVE-2024-46695 2024-10-17 23:15 2024-09-13 Show GitHub Exploit DB Packet Storm
311503 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix possible NULL pointer dereference in snd_usb_pcm_has_fixed_rate() The subs function argument may be NULL, so… CWE-476
 NULL Pointer Dereference
CVE-2023-52904 2024-10-17 23:15 2024-08-21 Show GitHub Exploit DB Packet Storm
311504 - - - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device shutdown. if health work started n… - CVE-2024-43866 2024-10-17 23:15 2024-08-21 Show GitHub Exploit DB Packet Storm
311505 6.1 MEDIUM
Network
phpoffice phpspreadsheet PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to imprope… CWE-79
Cross-site Scripting
CVE-2024-45060 2024-10-17 23:14 2024-10-8 Show GitHub Exploit DB Packet Storm
311506 5.5 MEDIUM
Local
fortra robot_schedule Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-8264 2024-10-17 23:06 2024-10-10 Show GitHub Exploit DB Packet Storm
311507 2.7 LOW
Network
mattermost mattermost_server Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL. NVD-CWE-noinfo
CVE-2024-40884 2024-10-17 23:05 2024-08-23 Show GitHub Exploit DB Packet Storm
311508 9.8 CRITICAL
Network
online_health_care_system_project online_health_care_system A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name … CWE-89
SQL Injection
CVE-2024-8080 2024-10-17 23:04 2024-08-23 Show GitHub Exploit DB Packet Storm
311509 6.5 MEDIUM
Network
ampache ampache ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). Cross-Site Request Forgery (CSRF) is a… CWE-352
 Origin Validation Error
CVE-2024-47828 2024-10-17 22:55 2024-10-10 Show GitHub Exploit DB Packet Storm
311510 4.3 MEDIUM
Network
enalean tuleap Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 1… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2024-47767 2024-10-17 22:50 2024-10-15 Show GitHub Exploit DB Packet Storm