Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1771 6.5 警告
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-8292 2026-05-18 12:09 2026-05-11 Show GitHub Exploit DB Packet Storm
1772 7.3 重要
Network
Mozilla Foundation Mozilla Firefox Mozilla FoundationのMozilla Firefoxにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-8390 2026-05-18 12:09 2026-05-12 Show GitHub Exploit DB Packet Storm
1773 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2025-12669 2026-05-18 12:08 2026-05-14 Show GitHub Exploit DB Packet Storm
1774 4.3 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-13874 2026-05-18 12:08 2026-05-14 Show GitHub Exploit DB Packet Storm
1775 7.5 重要
Network
GitLab.org GitLab GitLab.orgのGitLabにおける入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2025-14869 2026-05-18 12:08 2026-05-14 Show GitHub Exploit DB Packet Storm
1776 7.5 重要
Network
GitLab.org GitLab GitLab.orgのGitLabにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-14870 2026-05-18 12:08 2026-05-14 Show GitHub Exploit DB Packet Storm
1777 5.6 警告
Network
デル elastic cloud storage
Dell ObjectScale
デルのelastic cloud storage等の複数製品における認証回避の脆弱性 CWE-302
認証回避の脆弱性
CVE-2025-43992 2026-05-18 12:08 2026-05-11 Show GitHub Exploit DB Packet Storm
1778 6.7 警告
Local
フォーティネット FortiAP-U
FortiAP
FortiAP-W2
フォーティネットのFortiAP-U等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2025-53680 2026-05-18 12:08 2026-05-12 Show GitHub Exploit DB Packet Storm
1779 7.2 重要
Network
フォーティネット FortiMail フォーティネットのFortiMailにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-53681 2026-05-18 12:08 2026-05-12 Show GitHub Exploit DB Packet Storm
1780 8.8 重要
Network
フォーティネット FortiOS フォーティネットのFortiOSにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2025-53844 2026-05-18 12:08 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319131 6.1 MEDIUM
Network
webpack.js webpack Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. Th… CWE-79
Cross-site Scripting
CVE-2024-43788 2024-09-4 00:15 2024-08-28 Show GitHub Exploit DB Packet Storm
319132 5.9 MEDIUM
Network
matter-labs zksolc zksolc is a Solidity compiler for ZKsync. All LLVM versions since 2015 fold `(xor (shl 1, x), -1)` to `(rotl ~1, x)` if run with optimizations enabled. Here `~1` is generated as an unsigned 64 bits n… CWE-682
 Incorrect Calculation
CVE-2024-45056 2024-09-4 00:14 2024-08-30 Show GitHub Exploit DB Packet Storm
319133 6.1 MEDIUM
Network
collabora online Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject JavaScript via url e… CWE-79
Cross-site Scripting
CVE-2024-45045 2024-09-4 00:13 2024-08-30 Show GitHub Exploit DB Packet Storm
319134 - - - BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.) - CVE-2024-34463 2024-09-4 00:12 2024-09-3 Show GitHub Exploit DB Packet Storm
319135 8.8 HIGH
Network
muffingroup betheme The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This… CWE-502
 Deserialization of Untrusted Data
CVE-2024-2694 2024-09-4 00:10 2024-08-30 Show GitHub Exploit DB Packet Storm
319136 5.4 MEDIUM
Network
muffingroup betheme The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization… CWE-79
Cross-site Scripting
CVE-2024-3998 2024-09-4 00:00 2024-08-30 Show GitHub Exploit DB Packet Storm
319137 6.1 MEDIUM
Network
elecom wrc-x3000gs2-b_firmware
wrc-x3000gs2-w_firmware
wrc-x3000gs2a-b_firmware
Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, and WRC-X3000GS2A-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page whil… CWE-79
Cross-site Scripting
CVE-2024-34577 2024-09-3 23:59 2024-08-30 Show GitHub Exploit DB Packet Storm
319138 5.4 MEDIUM
Network
hubspot hubspot The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all version… CWE-79
Cross-site Scripting
CVE-2024-5879 2024-09-3 23:59 2024-08-30 Show GitHub Exploit DB Packet Storm
319139 3.7 LOW
Network
elecom wab-i1750-ps_firmware Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without … CWE-306
Missing Authentication for Critical Function
CVE-2024-39300 2024-09-3 23:57 2024-08-30 Show GitHub Exploit DB Packet Storm
319140 7.2 HIGH
Network
theeventscalendar events_calendar_pro The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in w… CWE-502
 Deserialization of Untrusted Data
CVE-2024-8016 2024-09-3 23:51 2024-08-30 Show GitHub Exploit DB Packet Storm