Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1681 7.4 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP デバイス ホストのリモートでコードが実行される脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32156 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
1682 7.5 重要
Network
jqlang jq jqlangのjqにおける複数の脆弱性 CWE-122
CWE-190
CVE-2026-32316 2026-04-24 11:31 2026-04-13 Show GitHub Exploit DB Packet Storm
1683 8.1 重要
Network
nginxui nginx ui Nginx UI TeamのNginx UIにおける複数の脆弱性 CWE-284
CWE-863
CVE-2026-33031 2026-04-24 11:31 2026-04-20 Show GitHub Exploit DB Packet Storm
1684 4.3 警告
Network
Docmost Docmost Docmostにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-33146 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
1685 8.1 重要
Network
tandoor recipes tandoorのrecipesにおけるHTTP ヘッダのスクリプト構文の不適切な無効化に関する脆弱性 CWE-644
HTTP ヘッダのスクリプト構文の不適切な無効化
CVE-2026-33149 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
1686 4.6 警告
Network
Docmost Docmost Docmostにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33193 2026-04-24 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
1687 6.5 警告
Network
Elasticsearch B.V. Kibana Elasticsearch B.V.のKibanaにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-33461 2026-04-24 11:30 2026-04-8 Show GitHub Exploit DB Packet Storm
1688 4.8 警告
Network
cryptomator cryptomator cryptomatorにおける複数の脆弱性 CWE-305
CWE-319
CVE-2026-33472 2026-04-24 11:30 2026-04-16 Show GitHub Exploit DB Packet Storm
1689 5.5 警告
Network
Pinchtab PinchTab PinchtabのPinchTabにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-33619 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
1690 6.5 警告
Network
Pinchtab PinchTab PinchtabのPinchTabにおける複数の脆弱性 CWE-290
CWE-770
CVE-2026-33621 2026-04-24 11:30 2026-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311 6.3 MEDIUM
Network
- - A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing … New CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-7653 2026-05-3 01:16 2026-05-3 Show GitHub Exploit DB Packet Storm
312 6.5 MEDIUM
Network
- - A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP … New CWE-22
Path Traversal
CVE-2026-7645 2026-05-3 01:16 2026-05-3 Show GitHub Exploit DB Packet Storm
313 7.3 HIGH
Network
- - A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote … New CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-7644 2026-05-3 00:16 2026-05-3 Show GitHub Exploit DB Packet Storm
314 4.3 MEDIUM
Network
- - A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cros… New CWE-346
CWE-942
 Origin Validation Error
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-7643 2026-05-3 00:16 2026-05-3 Show GitHub Exploit DB Packet Storm
315 6.3 MEDIUM
Network
- - A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation o… New CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-7642 2026-05-3 00:16 2026-05-3 Show GitHub Exploit DB Packet Storm
316 6.5 MEDIUM
Network
- - A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to… New CWE-73
 External Control of File Name or Path
CVE-2026-7633 2026-05-3 00:16 2026-05-3 Show GitHub Exploit DB Packet Storm
317 7.3 HIGH
Network
- - A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7632 2026-05-2 23:16 2026-05-2 Show GitHub Exploit DB Packet Storm
318 5.4 MEDIUM
Network
- - A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument U… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-7631 2026-05-2 23:16 2026-05-2 Show GitHub Exploit DB Packet Storm
319 7.3 HIGH
Network
- - A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of … CWE-287
Improper Authentication
CVE-2026-7630 2026-05-2 23:16 2026-05-2 Show GitHub Exploit DB Packet Storm
320 6.3 MEDIUM
Network
- - A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-7629 2026-05-2 23:16 2026-05-2 Show GitHub Exploit DB Packet Storm