Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1631 5.3 警告
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-44294 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1632 6.1 警告
Network
hono hono honoにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-44455 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1633 6.5 警告
Network
hono hono honoにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-44456 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1634 5.3 警告
Network
hono hono honoにおける重要な情報を含むキャッシュの使用に関する脆弱性 CWE-524
重要な情報を含むキャッシュの使用
CVE-2026-44457 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1635 4.3 警告
Network
hono hono honoにおける複数の脆弱性 CWE-116
CWE-74
CVE-2026-44458 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1636 3.8
Network
hono hono honoにおける入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2026-44459 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1637 7.5 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-44573 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1638 8.1 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-44574 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1639 7.5 重要
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-44575 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
1640 5.9 警告
Network
Vercel, Inc. (旧 Zeit, Inc.) Next.js Vercel, Inc. (旧 Zeit, Inc.)のNext.jsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-44577 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311661 9.1 CRITICAL
Network
gaizhenbiao chuanhuchatgpt A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files w… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2024-5823 2024-11-1 03:05 2024-10-29 Show GitHub Exploit DB Packet Storm
311662 - - - TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the book… - CVE-2024-34537 2024-11-1 02:15 2024-10-28 Show GitHub Exploit DB Packet Storm
311663 7.5 HIGH
Network
- - IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue m… CWE-266
 Incorrect Privilege Assignment
CVE-2024-40681 2024-11-1 02:15 2024-09-8 Show GitHub Exploit DB Packet Storm
311664 5.5 MEDIUM
Local
ibm mq_operator IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault. CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2024-40680 2024-11-1 02:15 2024-09-7 Show GitHub Exploit DB Packet Storm
311665 5.4 MEDIUM
Network
tychesoftwares arconix_shortcodes The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input saniti… CWE-79
Cross-site Scripting
CVE-2024-10226 2024-11-1 01:48 2024-10-29 Show GitHub Exploit DB Packet Storm
311666 8.8 HIGH
Network
ovaledge ovaledge OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required. NVD-CWE-noinfo
CVE-2022-30357 2024-11-1 01:43 2024-10-26 Show GitHub Exploit DB Packet Storm
311667 8.8 HIGH
Network
ovaledge ovaledge OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required. CWE-863
 Incorrect Authorization
CVE-2022-30358 2024-11-1 01:41 2024-10-26 Show GitHub Exploit DB Packet Storm
311668 5.4 MEDIUM
Network
fastlinemedia beaver_builder The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insuf… CWE-79
Cross-site Scripting
CVE-2024-9505 2024-11-1 01:39 2024-10-29 Show GitHub Exploit DB Packet Storm
311669 6.4 MEDIUM
Network
ovaledge ovaledge OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentic… CWE-79
Cross-site Scripting
CVE-2022-30360 2024-11-1 01:38 2024-10-26 Show GitHub Exploit DB Packet Storm
311670 4.3 MEDIUM
Network
ovaledge ovaledge OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with th… CWE-922
 Insecure Storage of Sensitive Information
CVE-2022-30359 2024-11-1 01:37 2024-10-26 Show GitHub Exploit DB Packet Storm