Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2051 5.4 警告
Network
lfprojects mlflow lfprojectsのmlflowにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33865 2026-04-21 10:43 2026-04-7 Show GitHub Exploit DB Packet Storm
2052 4.3 警告
Network
lfprojects mlflow lfprojectsのmlflowにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33866 2026-04-21 10:43 2026-04-7 Show GitHub Exploit DB Packet Storm
2053 9.1 緊急
Network
Mervin Praison (MervinPraison) PraisonAI Mervin Praison (MervinPraison)のPraisonAIにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-40313 2026-04-21 10:43 2026-04-14 Show GitHub Exploit DB Packet Storm
2054 6.5 警告
Network
PAC4J pac4j PAC4Jのpac4jにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40458 2026-04-21 10:43 2026-04-17 Show GitHub Exploit DB Packet Storm
2055 8.8 重要
Network
PAC4J pac4j PAC4Jのpac4jにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-40459 2026-04-21 10:43 2026-04-17 Show GitHub Exploit DB Packet Storm
2056 7.8 重要
Local
Rubicon Communications, LLC (Netgate). NETGATE Registry Cleaner Rubicon Communications, LLC (Netgate).のNETGATE Registry Cleanerにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2016-20057 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
2057 6.1 警告
Network
Thank You/Like System project Thank You/Like System MyBB GroupのThank You/Like Systemにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25247 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
2058 6.1 警告
Network
MyBB Group MyBB Last User's Threads MyBB GroupのMyBB Last User's Threadsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25250 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
2059 5.5 警告
Local
AnyBurn AnyBurn AnyBurnにおける再利用前に削除されていないリソース内重要情報に関する脆弱性 CWE-226
再利用前に削除されていないリソース内重要情報
CVE-2019-25657 2026-04-21 10:43 2026-04-5 Show GitHub Exploit DB Packet Storm
2060 5.5 警告
Local
Hainsoft.com LanHelper Hainsoft.comのLanHelperにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2019-25660 2026-04-21 10:43 2026-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311 7.5 HIGH
Network
- - Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial … Update CWE-617
 Reachable Assertion
CVE-2025-56568 2026-05-5 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
312 7.5 HIGH
Network
- - An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request Update CWE-20
CWE-400
 Improper Input Validation 
 Uncontrolled Resource Consumption
CVE-2025-46115 2026-05-5 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
313 9.8 CRITICAL
Network
cpanel cpanel
whm
wp_squared
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Update CWE-306
Missing Authentication for Critical Function
CVE-2026-41940 2026-05-5 03:09 2026-04-30 Show GitHub Exploit DB Packet Storm
314 6.5 MEDIUM
Network
gnu glibc The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing… Update CWE-126
 Buffer Over-read
CVE-2026-6238 2026-05-5 02:57 2026-04-29 Show GitHub Exploit DB Packet Storm
315 9.9 CRITICAL
Network
- - In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table … New CWE-20
CWE-284
CWE-732
CWE-863
 Improper Input Validation 
Improper Access Control
 Incorrect Permission Assignment for Critical Resource
 Incorrect Authorization
CVE-2026-42812 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
316 9.9 CRITICAL
Network
- - In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across … New CWE-20
CWE-917
 Improper Input Validation 
 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2026-42811 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
317 9.9 CRITICAL
Network
- - Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary crede… New CWE-20
CWE-862
 Improper Input Validation 
 Missing Authorization
CVE-2026-42809 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
318 9.8 CRITICAL
Network
- - D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-42376 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
319 9.8 CRITICAL
Network
- - D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-42375 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
320 9.8 CRITICAL
Network
- - D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-42374 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm