Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1931 8.1 重要
Network
VMware Spring Cloud Config VMwareのSpring Cloud ConfigにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41002 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
1932 4.4 警告
Local
VMware Spring Cloud Config VMwareのSpring Cloud Configにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-41004 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
1933 5.3 警告
Network
Sync-in Sync-in Server Sync-inのSync-in Serverにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-41161 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1934 5.3 警告
Network
angular angular angularにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41423 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1935 8.1 重要
Network
Linux Foundation dapr Linux Foundationのdaprにおける複数の脆弱性 CWE-22
CWE-284
CWE-noinfo
CVE-2026-41491 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1936 7.5 重要
Network
Loren Segal YARD Loren SegalのYARDにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41493 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1937 3.3
Network
Kimai project kimai Kimai projectのKimaiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41498 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1938 7.4 重要
Network
go-git project go-git go-git projectのgo-gitにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-41506 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1939 8.1 重要
Network
Andreas Kloeckner RELATE Andreas KloecknerのRELATEにおける複数の脆弱性 CWE-203
CWE-208
CVE-2026-41588 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
1940 8.8 重要
Network
NocoBase NocoBase NocoBaseにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-41640 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311791 - - - golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2024-51744 2024-11-6 01:04 2024-11-5 Show GitHub Exploit DB Packet Storm
311792 - - - A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without the… - CVE-2024-30617 2024-11-6 01:04 2024-11-5 Show GitHub Exploit DB Packet Storm
311793 - - - Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity. - CVE-2024-30616 2024-11-6 01:04 2024-11-5 Show GitHub Exploit DB Packet Storm
311794 6.1 MEDIUM
Network
cisco firepower_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS… CWE-79
Cross-site Scripting
CVE-2024-20372 2024-11-6 01:04 2024-10-24 Show GitHub Exploit DB Packet Storm
311795 4.6 MEDIUM
Network
radixiot mango MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page. CWE-94
Code Injection
CVE-2024-37846 2024-11-6 01:03 2024-10-26 Show GitHub Exploit DB Packet Storm
311796 5.4 MEDIUM
Network
radixiot mango A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. CWE-79
Cross-site Scripting
CVE-2024-37844 2024-11-6 01:03 2024-10-26 Show GitHub Exploit DB Packet Storm
311797 5.4 MEDIUM
Network
cisco firepower_management_center A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due … CWE-79
Cross-site Scripting
CVE-2024-20387 2024-11-6 01:00 2024-10-24 Show GitHub Exploit DB Packet Storm
311798 8.8 HIGH
Network
radixiot mangoapi
mango
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file. CWE-22
Path Traversal
CVE-2024-37847 2024-11-6 00:47 2024-10-26 Show GitHub Exploit DB Packet Storm
311799 - - - An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation. - CVE-2024-48217 2024-11-6 00:35 2024-11-2 Show GitHub Exploit DB Packet Storm
311800 8.4 HIGH
Local
cisco firepower_threat_defense A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system usin… CWE-798
 Use of Hard-coded Credentials
CVE-2024-20412 2024-11-6 00:03 2024-10-24 Show GitHub Exploit DB Packet Storm