Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1971 5.5 警告
Local
jqlang jq jqlangのjqにおける複数の脆弱性 CWE-190
CWE-787
CVE-2026-41257 2026-05-15 11:01 2026-05-11 Show GitHub Exploit DB Packet Storm
1972 5.4 警告
Network
Langfuse GmbH Langfuse Langfuse GmbHのLangfuseにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-41487 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
1973 9.8 緊急
Network
Nhost Nhost/auth NhostのNhost/authにおける認証に関する脆弱性 CWE-287
CWE-noinfo
CVE-2026-41574 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
1974 7.5 重要
Network
Web Technologies Change Detection Web TechnologiesのChange DetectionにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-41895 2026-05-15 11:00 2026-05-12 Show GitHub Exploit DB Packet Storm
1975 9.8 緊急
Network
レッドハット
GNU Project
Red Hat OpenShift Container Platform
Red Hat Hardened Images
GnuTLS
Red Hat Enterprise Linux
GNU Project等の複数ベンダの製品におけるNull バイト相互作用エラー (Poison Null Byte) の脆弱性 CWE-626
Null バイト相互作用エラー (Poison Null Byte)
CVE-2026-42010 2026-05-15 11:00 2026-05-7 Show GitHub Exploit DB Packet Storm
1976 9.6 緊急
Network
langflow langflow langflowにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-42048 2026-05-15 11:00 2026-05-12 Show GitHub Exploit DB Packet Storm
1977 5.5 警告
Local
ImageMagick ImageMagick ImageMagickにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-42050 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
1978 8.1 重要
Network
- OpenC3のOpenC3 COSMOSにおける不要な特権による実行に関する脆弱性 CWE-250
不要な特権による実行
CVE-2026-42088 2026-05-15 11:00 2026-05-4 Show GitHub Exploit DB Packet Storm
1979 8.8 重要
Network
litellm litellm LiteLLMにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-42203 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
1980 9.1 緊急
Network
axios project axios axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42264 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2401 5.5 MEDIUM
Local
- - A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data. CWE-284
Improper Access Control
CVE-2025-46307 2026-05-27 23:51 2026-05-27 Show GitHub Exploit DB Packet Storm
2402 7.1 HIGH
Network
- - Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n… CWE-862
 Missing Authorization
CVE-2025-14361 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2403 7.3 HIGH
Network
- - A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access cont… CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9580 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2404 4.3 MEDIUM
Network
- - A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site … CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2026-9582 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2405 7.3 HIGH
Network
- - A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql in… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9584 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2406 6.5 MEDIUM
Network
- - A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument I… CWE-862
CWE-863
 Missing Authorization
 Incorrect Authorization
CVE-2026-9603 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2407 4.3 MEDIUM
Network
- - A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improp… CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9604 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2408 7.3 HIGH
Network
- - A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9606 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2409 6.4 MEDIUM
Network
- - The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endp… CWE-79
Cross-site Scripting
CVE-2026-6565 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2410 5.3 MEDIUM
Network
- - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-7493 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm