Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2121 5.8 警告
Network
vm2 project vm2 vm2 projectのvm2におけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2026-44002 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
2122 5.8 警告
Network
vm2 project vm2 vm2 projectのvm2における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-44003 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2123 7.5 重要
Network
vm2 project vm2 vm2 projectのvm2における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-44004 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2124 10 緊急
Network
vm2 project vm2 vm2 projectのvm2における複数の脆弱性 CWE-1321
CWE-94
CVE-2026-44005 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2125 10 緊急
Network
vm2 project vm2 vm2 projectのvm2におけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-44006 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2126 9.1 緊急
Network
vm2 project vm2 vm2 projectのvm2におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-44007 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2127 9.8 緊急
Network
vm2 project vm2 vm2 projectのvm2における誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2026-44008 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2128 9.8 緊急
Network
vm2 project vm2 vm2 projectのvm2における誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2026-44009 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
2129 9.9 緊急
Network
nginxui Nginx UI Nginx UI TeamのNginx UIにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-44015 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
2130 7.1 重要
Network
M2-Team NanaZip M2-TeamのNanaZipにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-44215 2026-05-18 12:12 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318951 9.8 CRITICAL
Network
ruoyi ruoyi RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1. CWE-89
SQL Injection
CVE-2024-42913 2024-09-6 03:31 2024-08-27 Show GitHub Exploit DB Packet Storm
318952 9.8 CRITICAL
Network
skyss arfa-cms A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter. CWE-89
SQL Injection
CVE-2024-45265 2024-09-6 03:30 2024-08-27 Show GitHub Exploit DB Packet Storm
318953 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses Currently, it's possible to pass in a modified… CWE-787
 Out-of-bounds Write
CVE-2024-43910 2024-09-6 03:30 2024-08-26 Show GitHub Exploit DB Packet Storm
318954 6.1 MEDIUM
Network
testlink testlink TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name. CWE-79
Cross-site Scripting
CVE-2024-42906 2024-09-6 03:29 2024-08-27 Show GitHub Exploit DB Packet Storm
318955 7.5 HIGH
Network
gl-inet mt6000_firmware
x3000_firmware
xe3000_firmware
a1300_firmware
ax1800_firmware
axt1800_firmware
mt2500_firmware
mt3000_firmware
xe300_firmware
x750_firmware
sft1200_firmw…
A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports … NVD-CWE-noinfo
CVE-2024-28077 2024-09-6 03:29 2024-08-27 Show GitHub Exploit DB Packet Storm
318956 6.1 MEDIUM
Network
xiebruce picuploader A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted pay… CWE-79
Cross-site Scripting
CVE-2024-44794 2024-09-6 03:28 2024-08-27 Show GitHub Exploit DB Packet Storm
318957 6.1 MEDIUM
Network
gazelle_project gazelle A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload … CWE-79
Cross-site Scripting
CVE-2024-44793 2024-09-6 03:28 2024-08-27 Show GitHub Exploit DB Packet Storm
318958 6.1 MEDIUM
Network
gazelle_project gazelle A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… CWE-79
Cross-site Scripting
CVE-2024-44795 2024-09-6 03:26 2024-08-27 Show GitHub Exploit DB Packet Storm
318959 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: disallow setting special AP channel widths Setting the AP channel width is meant for use with the normal 20/40/...… NVD-CWE-noinfo
CVE-2024-43912 2024-09-6 03:19 2024-08-26 Show GitHub Exploit DB Packet Storm
318960 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme: apple: fix device reference counting Drivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl. Split the alloca… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2024-43913 2024-09-6 03:12 2024-08-26 Show GitHub Exploit DB Packet Storm