Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2051 5.3 警告
Network
Apache Software Foundation Apache Thrift Apache Software FoundationのApache Thriftにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-41606 2026-04-30 10:59 2026-04-28 Show GitHub Exploit DB Packet Storm
2052 6.5 警告
Network
Apache Software Foundation Apache Thrift Apache Software FoundationのApache Thriftにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-41607 2026-04-30 10:59 2026-04-28 Show GitHub Exploit DB Packet Storm
2053 7.5 重要
Network
Apache Software Foundation Apache Thrift Apache Software FoundationのApache Thriftにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-41636 2026-04-30 10:59 2026-04-28 Show GitHub Exploit DB Packet Storm
2054 7.5 重要
Network
Marked project Marked Marked projectのMarkedにおける複数の脆弱性 CWE-400
CWE-674
CWE-835
CVE-2026-41680 2026-04-30 10:59 2026-04-24 Show GitHub Exploit DB Packet Storm
2055 9.8 緊急
Network
Apache Software Foundation Apache Pony Mail Apache Software FoundationのApache Pony MailにおけるHTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2026-41873 2026-04-30 10:59 2026-04-28 Show GitHub Exploit DB Packet Storm
2056 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41908 2026-04-30 10:58 2026-04-23 Show GitHub Exploit DB Packet Storm
2057 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41909 2026-04-30 10:58 2026-04-23 Show GitHub Exploit DB Packet Storm
2058 8.8 重要
Network
GitHub Enterprise Server GitHubのEnterprise Serverにおける不正な正規表現に関する脆弱性 CWE-185
不正な正規表現
CVE-2026-4296 2026-04-30 10:58 2026-04-21 Show GitHub Exploit DB Packet Storm
2059 8.8 重要
Network
Kubernetes ingress-nginx Kubernetesのingress-nginxにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-4342 2026-04-30 10:58 2026-03-19 Show GitHub Exploit DB Packet Storm
2060 6.5 警告
Network
レッドハット
libarchive
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux
Red Hat Hardened Images
libarchive
libarchive等の複数ベンダの製品における整数への不適切なビットシフトに関する脆弱性 CWE-1335
整数への不適切なビットシフト
CVE-2026-4426 2026-04-30 10:58 2026-03-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313811 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. CWE-89
SQL Injection
CVE-2024-5556 2024-08-27 23:36 2024-08-23 Show GitHub Exploit DB Packet Storm
313812 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. CWE-89
SQL Injection
CVE-2024-5490 2024-08-27 23:36 2024-08-23 Show GitHub Exploit DB Packet Storm
313813 - - - A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… - CVE-2024-42816 2024-08-27 23:35 2024-08-27 Show GitHub Exploit DB Packet Storm
313814 6.1 MEDIUM
Network
zohocorp manageengine_servicedesk_plus_msp
manageengine_servicedesk_plus
manageengine_supportcenter_plus
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions… CWE-79
Cross-site Scripting
CVE-2024-41150 2024-08-27 23:35 2024-08-24 Show GitHub Exploit DB Packet Storm
313815 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report. CWE-89
SQL Injection
CVE-2024-5467 2024-08-27 23:35 2024-08-23 Show GitHub Exploit DB Packet Storm
313816 6.1 MEDIUM
Network
blood_bank_system_project blood_bank_system A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login.php of the component… CWE-79
Cross-site Scripting
CVE-2024-8174 2024-08-27 23:32 2024-08-27 Show GitHub Exploit DB Packet Storm
313817 9.8 CRITICAL
Network
tenda ax1806_firmware Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo. CWE-787
 Out-of-bounds Write
CVE-2024-44557 2024-08-27 23:30 2024-08-27 Show GitHub Exploit DB Packet Storm
313818 9.8 CRITICAL
Network
tenda ax1806_firmware Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. CWE-787
 Out-of-bounds Write
CVE-2024-44555 2024-08-27 23:29 2024-08-27 Show GitHub Exploit DB Packet Storm
313819 9.8 CRITICAL
Network
tenda ax1806_firmware Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. CWE-787
 Out-of-bounds Write
CVE-2024-44553 2024-08-27 23:29 2024-08-27 Show GitHub Exploit DB Packet Storm
313820 9.8 CRITICAL
Network
tenda ax1806_firmware Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. CWE-787
 Out-of-bounds Write
CVE-2024-44552 2024-08-27 23:29 2024-08-27 Show GitHub Exploit DB Packet Storm