Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1941 6.1 警告
Network
fast-xml-parser project fast-xml-parser Natural Intelligenceのfast-xml-parserにおけるブラインド XPath インジェクションの脆弱性 CWE-91
ブラインド XPath インジェクション
CVE-2026-41650 2026-05-14 10:18 2026-05-7 Show GitHub Exploit DB Packet Storm
1942 4.4 警告
Local
Anthropic PBC Claude SDK for TypeScript (anthropic-ai/sdk) Anthropic PBCのClaude SDK for TypeScript (anthropic-ai/sdk)における重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2026-41686 2026-05-14 10:18 2026-05-4 Show GitHub Exploit DB Packet Storm
1943 8.6 重要
Network
VMware Spring AI VMwareのSpring AIにおける言語構文の表現に使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-917
言語構文の表現に使用される特殊な要素の不適切な無効化
CVE-2026-41705 2026-05-14 10:18 2026-05-9 Show GitHub Exploit DB Packet Storm
1944 7.5 重要
Network
VMware Spring AI VMwareのSpring AIにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2026-41712 2026-05-14 10:18 2026-05-12 Show GitHub Exploit DB Packet Storm
1945 8.2 重要
Network
VMware Spring AI VMwareのSpring AIにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-41713 2026-05-14 10:18 2026-05-12 Show GitHub Exploit DB Packet Storm
1946 6.5 警告
Network
LangGenius Dify LangGeniusのDifyにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41950 2026-05-14 10:18 2026-05-5 Show GitHub Exploit DB Packet Storm
1947 9.6 緊急
Network
Streetwriters Notesnook Mobile
Notesnook Desktop
StreetwritersのNotesnook Desktop等の複数製品における複数の脆弱性 CWE-79
CWE-94
CVE-2026-42090 2026-05-14 10:18 2026-05-4 Show GitHub Exploit DB Packet Storm
1948 6.5 警告
Network
goshs goshs goshsにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-42091 2026-05-14 10:18 2026-05-4 Show GitHub Exploit DB Packet Storm
1949 4.8 警告
Network
Weblate wlc Weblateのwlcにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42150 2026-05-14 10:18 2026-05-8 Show GitHub Exploit DB Packet Storm
1950 5.9 警告
Network
Teluu Ltd. PJSIP Teluu Ltd.のPJSIPにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-42225 2026-05-14 10:18 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311761 8.8 HIGH
Network
esafenet cdg A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation … CWE-89
SQL Injection
CVE-2024-10501 2024-11-7 02:20 2024-10-30 Show GitHub Exploit DB Packet Storm
311762 5.4 MEDIUM
Network
neumann n-line N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be direct… CWE-94
Code Injection
CVE-2024-47158 2024-11-7 02:10 2024-10-25 Show GitHub Exploit DB Packet Storm
311763 7.5 HIGH
Network
neumann musasi MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved. NVD-CWE-Other
CVE-2024-45785 2024-11-7 02:08 2024-10-25 Show GitHub Exploit DB Packet Storm
311764 9.8 CRITICAL
Network
dfactory responsive_lightbox Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7. CWE-862
 Missing Authorization
CVE-2024-43924 2024-11-7 02:03 2024-10-23 Show GitHub Exploit DB Packet Storm
311765 6.5 MEDIUM
Network
sonatype nexus Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (… CWE-798
 Use of Hard-coded Credentials
CVE-2024-5764 2024-11-7 01:41 2024-10-24 Show GitHub Exploit DB Packet Storm
311766 7.2 HIGH
Network
wuzhicms wuzhicms A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to cod… CWE-94
Code Injection
CVE-2024-10505 2024-11-7 01:38 2024-10-30 Show GitHub Exploit DB Packet Storm
311767 - - - Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially … - CVE-2023-31305 2024-11-7 01:35 2024-08-14 Show GitHub Exploit DB Packet Storm
311768 9.8 CRITICAL
Network
esafenet cdg A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation … CWE-89
SQL Injection
CVE-2024-10597 2024-11-7 01:28 2024-11-1 Show GitHub Exploit DB Packet Storm
311769 5.3 MEDIUM
Network
choplugins order_notification_for_telegram The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions u… CWE-862
 Missing Authorization
CVE-2024-9686 2024-11-7 01:19 2024-10-25 Show GitHub Exploit DB Packet Storm
311770 3.6 LOW
Local
chidiwilliams buzz A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to ins… CWE-377
 Insecure Temporary File
CVE-2024-10372 2024-11-7 01:14 2024-10-25 Show GitHub Exploit DB Packet Storm