Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
141 6.5 警告
Network
vLLM vLLM vLLMにおける複数の脆弱性 New CWE-131
CWE-704
CVE-2026-44223 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
142 8.8 重要
Network
requarks Wiki.js requarksのWiki.jsにおける権限管理に関する脆弱性 New CWE-269
CWE-noinfo
CVE-2026-44224 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
143 6.5 警告
Network
warpgate project warpgate Warpgate projectのWarpgateにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-44347 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
144 7.2 重要
Network
WING FTP software Wing FTP Server WING FTP softwareのWing FTP Serverにおけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2026-44403 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
145 5.3 警告
Network
Python Software Foundation urllib3 Python Software Foundationのurllib3における情報漏えいに関する脆弱性 New CWE-200
CWE-noinfo
CVE-2026-44431 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
146 7.5 重要
Network
Python Software Foundation urllib3 Python Software Foundationのurllib3における高圧縮データの処理 (データ増幅)に関する脆弱性 New CWE-409
高圧縮データの不適切な処理 (データ増幅)
CVE-2026-44432 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
147 5.7 警告
Adjacent
Frappe ERPNext FrappeのERPNextにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-44440 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
148 4.3 警告
Network
Frappe ERPNext FrappeのERPNextにおけるサーバサイドのリクエストフォージェリの脆弱性 New CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-44441 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
149 9.9 緊急
Network
Frappe ERPNext FrappeのERPNextにおける認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2026-44442 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
150 6.5 警告
Network
Frappe ERPNext FrappeのERPNextにおけるXML 外部エンティティの脆弱性 New CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-44445 2026-05-18 12:11 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311891 - - - DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter. - CVE-2024-41584 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311892 - - - DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name. - CVE-2024-41583 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311893 - - - Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly i… CWE-440
 Expected Behavior Violation
CVE-2024-47762 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311894 - - - TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTT… CWE-306
Missing Authentication for Critical Function
CVE-2024-41988 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311895 - - - The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exp… CWE-352
 Origin Validation Error
CVE-2024-41987 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311896 - - - Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files. - CVE-2024-45872 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311897 - - - Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). - CVE-2024-45871 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311898 - - - NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A s… CWE-476
 NULL Pointer Dereference
CVE-2024-0125 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311899 - - - NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A succ… CWE-416
 Use After Free
CVE-2024-0124 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311900 - - - NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into runnin… CWE-1285
 Improper Validation of Specified Index, Position, or Offset in Input
CVE-2024-0123 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm