Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2091 7.1 重要
Network
SalesAgility SuiteCRM SalesAgilityのSuiteCRMにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2019-25663 2026-04-21 10:40 2026-04-5 Show GitHub Exploit DB Packet Storm
2092 7.1 重要
Network
SalesAgility SuiteCRM SalesAgilityのSuiteCRMにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2019-25664 2026-04-21 10:40 2026-04-5 Show GitHub Exploit DB Packet Storm
2093 5.5 警告
Local
Nsasoft US LLC. SpotAuditor Nsasoft US LLC.のSpotAuditorにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2019-25666 2026-04-21 10:40 2026-04-5 Show GitHub Exploit DB Packet Storm
2094 7.5 重要
Network
Georgia Tech Computing For Good's Basic Laboratory Information System Georgia TechのComputing For Good's Basic Laboratory Information Systemにおける複数の脆弱性 CWE-306
CWE-89
CVE-2019-25678 2026-04-21 10:40 2026-04-5 Show GitHub Exploit DB Packet Storm
2095 7.8 重要
Local
Simon Bridger (crun) RealTerm Simon Bridger (crun)のRealTermにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2019-25679 2026-04-21 10:40 2026-04-5 Show GitHub Exploit DB Packet Storm
2096 4.3 警告
Network
フォーティネット FortiVoice
FortiNDR
フォーティネットのFortiNDR等の複数製品における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2024-23104 2026-04-21 10:40 2026-04-14 Show GitHub Exploit DB Packet Storm
2097 6.5 警告
Network
Grafana Labs Grafana Grafana LabsのGrafanaにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2025-12141 2026-04-21 10:40 2026-04-15 Show GitHub Exploit DB Packet Storm
2098 7.8 重要
Local
Truesec LAPSWebUI TruesecのLAPSWebUIにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2025-15552 2026-04-21 10:40 2026-03-16 Show GitHub Exploit DB Packet Storm
2099 7.1 重要
Local
Truesec LAPSWebUI TruesecのLAPSWebUIにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2025-15553 2026-04-21 10:40 2026-03-16 Show GitHub Exploit DB Packet Storm
2100 7.8 重要
Local
デル data domain operating system デルのdata domain operating systemにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2025-36568 2026-04-21 10:40 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
261 7.5 HIGH
Network
- - Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/a… New CWE-200
CWE-312
Information Exposure
 Cleartext Storage of Sensitive Information
CVE-2026-42151 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
262 - - - Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in … New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41686 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
263 7.5 HIGH
Network
- - Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fiel… New CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-25863 2026-05-5 04:16 2026-05-5 Show GitHub Exploit DB Packet Storm
264 5.5 MEDIUM
Local
absolute secure_access CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-40951 2026-05-5 03:54 2026-05-1 Show GitHub Exploit DB Packet Storm
265 9.8 CRITICAL
Network
tenda w308r_firmware Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25316 2026-05-5 03:42 2026-04-30 Show GitHub Exploit DB Packet Storm
266 9.8 CRITICAL
Network
tenda fh303_firmware
a300_firmware
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25318 2026-05-5 03:40 2026-04-30 Show GitHub Exploit DB Packet Storm
267 5.0 MEDIUM
Network
cloudfoundry cf-deployment
routing_release
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure… Update CWE-923
 Improper Restriction of Communication Channel to Intended Endpoints
CVE-2026-22726 2026-05-5 03:30 2026-05-1 Show GitHub Exploit DB Packet Storm
268 7.5 HIGH
Network
openstack ironic_python_agent An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading … Update CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-43003 2026-05-5 03:28 2026-05-1 Show GitHub Exploit DB Packet Storm
269 9.8 CRITICAL
Network
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a clon… Update CWE-787
 Out-of-bounds Write
CVE-2026-43037 2026-05-5 03:26 2026-05-2 Show GitHub Exploit DB Packet Storm
270 8.5 HIGH
Network
openstack keystone An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authentica… Update CWE-863
 Incorrect Authorization
CVE-2026-43001 2026-05-5 03:25 2026-05-1 Show GitHub Exploit DB Packet Storm