Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
161 7.1 重要
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-3473 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
162 6.7 警告
Local
デル smartfabric storage software デルのsmartfabric storage softwareにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-35070 2026-05-28 14:42 2026-05-20 Show GitHub Exploit DB Packet Storm
163 4.3 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-3636 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
164 6.5 警告
Network
The Go Project crypto The Go Projectのcryptoにおける通信チャネルで送信中のメッセージの整合性への不適切な強制に関する脆弱性 CWE-924
通信チャネルで送信中のメッセージの整合性への不適切な強制
CVE-2026-39827 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
165 3.3
Local
Artifex Software MuPDF Artifex SoftwareのMuPDFにおけるエスケープ、メタ、またはコントロールシーケンスの不適切な無効化に関する脆弱性 CWE-150
エスケープ、メタ、またはコントロールシーケンスの不適切な無効化
CVE-2026-40505 2026-05-28 14:42 2026-04-16 Show GitHub Exploit DB Packet Storm
166 7.5 重要
Network
NLnet Labs unbound NLnet Labsのunboundにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-40622 2026-05-28 14:42 2026-05-20 Show GitHub Exploit DB Packet Storm
167 4.8 警告
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-41999 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
168 8.6 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-42000 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
169 7.5 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-42001 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
170 7.5 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるシグナルハンドラの競合状態に関する脆弱性 CWE-364
シグナルハンドラの競合状態
CVE-2026-42002 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311121 - - - The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloa… - CVE-2024-46960 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311122 - - - The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user intera… - CVE-2024-36064 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311123 - - - The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted … - CVE-2024-36063 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311124 - - - An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!"… - CVE-2019-20472 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311125 - - - An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker w… - CVE-2019-20469 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311126 - - - An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. … - CVE-2019-20461 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311127 - - - An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request is from a legitimate so… - CVE-2019-20460 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311128 - - - An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet. - CVE-2024-51428 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311129 - - - An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through … - CVE-2020-11926 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm
311130 - - - An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. … - CVE-2020-11921 2024-11-9 02:35 2024-11-8 Show GitHub Exploit DB Packet Storm