Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1801 4.9 警告
Network
aiven Aiven Operator aivenのAiven Operatorにおける複数の脆弱性 CWE-269
CWE-441
CVE-2026-39961 2026-05-15 10:54 2026-04-9 Show GitHub Exploit DB Packet Storm
1802 8.8 重要
Network
AGiXT AGiXT AGiXTにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-39981 2026-05-15 10:54 2026-04-9 Show GitHub Exploit DB Packet Storm
1803 7.5 重要
Network
Succinct SP1 SuccinctのSP1における複数の脆弱性 CWE-345
CWE-354
CVE-2026-40323 2026-05-15 10:54 2026-04-18 Show GitHub Exploit DB Packet Storm
1804 8.8 重要
Network
Electric Sync-service ElectricのSync-serviceにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-40906 2026-05-15 10:54 2026-04-21 Show GitHub Exploit DB Packet Storm
1805 6.5 警告
Network
Apache Software Foundation Apache-airflow-providers-elasticsearch Apache Software FoundationのApache-airflow-providers-elasticsearchにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-41018 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
1806 6.5 警告
Network
BETTER-AUTH. Better Auth OAuth Provider BETTER-AUTH.のBetter Auth OAuth Providerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41427 2026-05-15 10:54 2026-04-24 Show GitHub Exploit DB Packet Storm
1807 8.6 重要
Network
Inngest Inngest Inngestにおける複数の脆弱性 CWE-200
CWE-497
CVE-2026-42047 2026-05-15 10:54 2026-05-7 Show GitHub Exploit DB Packet Storm
1808 8.5 重要
Network
Open edX Open edx Enterprise Service Open edXのOpen edx Enterprise Serviceにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-42860 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
1809 6.5 警告
Network
Apache Software Foundation Apache-airflow-providers-opensearch Apache Software FoundationのApache-airflow-providers-opensearchにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-43826 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
1810 6.8 警告
Network
Bpple (bx33661) Wireshark MCP Bpple (bx33661)のWireshark MCPにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-43901 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311851 8.8 HIGH
Network
mozilla thunderbird
firefox
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could… CWE-787
 Out-of-bounds Write
CVE-2024-10467 2024-11-4 22:26 2024-10-29 Show GitHub Exploit DB Packet Storm
311852 6.1 MEDIUM
Network
mozilla thunderbird
firefox
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affe… CWE-79
Cross-site Scripting
CVE-2024-10461 2024-11-4 22:25 2024-10-29 Show GitHub Exploit DB Packet Storm
311853 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tracing: Free buffers when a used dynamic event is removed After 65536 dynamic events have been added and removed, the "type" fie… CWE-416
 Use After Free
CVE-2022-49006 2024-11-4 22:16 2024-10-22 Show GitHub Exploit DB Packet Storm
311854 - - - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. - CVE-2024-48342 2024-11-4 16:15 2024-11-4 Show GitHub Exploit DB Packet Storm
311855 10.0 CRITICAL
Network
- - IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and ex… CWE-78
OS Command 
CVE-2024-10653 2024-11-4 16:15 2024-11-1 Show GitHub Exploit DB Packet Storm
311856 - - - An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third part… - CVE-2024-51427 2024-11-4 15:15 2024-10-31 Show GitHub Exploit DB Packet Storm
311857 - - - An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third… - CVE-2024-51426 2024-11-4 15:15 2024-10-31 Show GitHub Exploit DB Packet Storm
311858 - - - An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this is disputed by third parties because the impa… - CVE-2024-51425 2024-11-4 15:15 2024-10-31 Show GitHub Exploit DB Packet Storm
311859 - - - An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by … - CVE-2024-51424 2024-11-4 15:15 2024-10-31 Show GitHub Exploit DB Packet Storm
311860 - - - In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not need… - CVE-2024-20124 2024-11-4 11:15 2024-11-4 Show GitHub Exploit DB Packet Storm