Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2151 5.9 警告
Network
マイクロソフト Microsoft .NET Framework .NET Framework のサービス拒否の脆弱性 CWE-362
競合状態
CVE-2026-32226 2026-05-8 12:23 2026-04-14 Show GitHub Exploit DB Packet Storm
2152 8.8 重要
Network
Kubernetes ingress-nginx Kubernetesのingress-nginxにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-3288 2026-05-8 12:23 2026-03-9 Show GitHub Exploit DB Packet Storm
2153 7.5 重要
Network
マイクロソフト Microsoft .NET Framework
.NET
.NET、.NET Framework、Visual Studio のサービス拒否の脆弱性 CWE-20
CWE-400
CWE-835
CVE-2026-33116 2026-05-8 12:23 2026-04-14 Show GitHub Exploit DB Packet Storm
2154 8.8 重要
Network
マイクロソフト SQL Server 2016
SQL Server 2017
SQL Server 2022
SQL Server 2019
SQL Server 2025
Microsoft SQL Server のリモート コードが実行される脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-33120 2026-05-8 12:23 2026-04-14 Show GitHub Exploit DB Packet Storm
2155 5.9 警告
Network
Apache Software Foundation Apache Log4j Apache Software FoundationのApache Log4jにおける複数の脆弱性 CWE-295
CWE-297
CVE-2026-34477 2026-05-8 12:23 2026-04-10 Show GitHub Exploit DB Packet Storm
2156 7.5 重要
Network
Apache Software Foundation Apache Log4j Apache Software FoundationのApache Log4jにおけるエンコードおよびエスケープに関する脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2026-34479 2026-05-8 12:23 2026-04-10 Show GitHub Exploit DB Packet Storm
2157 7.4 重要
Network
GNU Project
レッドハット
Red Hat Hardened Images
Red Hat Enterprise Linux
Red Hat OpenShift Container Platform
GnuTLS
GNU Project等の複数ベンダの製品における大文字と小文字の区別の不適切な処理に関する脆弱性 CWE-178
大文字と小文字の区別の不適切な処理
CVE-2026-3833 2026-05-8 12:23 2026-04-30 Show GitHub Exploit DB Packet Storm
2158 9.1 緊急
Network
Apache Software Foundation Apache Wicket Apache Software FoundationのApache Wicketにおけるセッションの固定化の脆弱性 CWE-384
CWE-384
CVE-2026-40010 2026-05-8 12:23 2026-05-6 Show GitHub Exploit DB Packet Storm
2159 9.1 緊急
Network
Apache Software Foundation Apache OpenNLP Apache Software FoundationのApache OpenNLPにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-40682 2026-05-8 12:23 2026-05-4 Show GitHub Exploit DB Packet Storm
2160 9.8 緊急
Network
Apache Software Foundation Apache OpenNLP Apache Software FoundationのApache OpenNLPにおけるクラスまたはコードを選択する外部から制御された入力の使用に関する脆弱性 CWE-470
クラスまたはコードを選択する外部から制御された入力の使用
CVE-2026-42027 2026-05-8 12:23 2026-05-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312491 - - - In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not need… - CVE-2024-20099 2024-10-7 12:15 2024-10-7 Show GitHub Exploit DB Packet Storm
312492 - - - In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not need… - CVE-2024-20098 2024-10-7 12:15 2024-10-7 Show GitHub Exploit DB Packet Storm
312493 - - - In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede… - CVE-2024-20092 2024-10-7 12:15 2024-10-7 Show GitHub Exploit DB Packet Storm
312494 - - - In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede… - CVE-2024-20090 2024-10-7 12:15 2024-10-7 Show GitHub Exploit DB Packet Storm
312495 6.5 MEDIUM
Network
online_voting_system_project online_voting_system Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by a… CWE-352
 Origin Validation Error
CVE-2024-45987 2024-10-5 11:21 2024-09-27 Show GitHub Exploit DB Packet Storm
312496 5.4 MEDIUM
Network
websevendev attributes_for_blocks The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 due to insufficient inp… CWE-79
Cross-site Scripting
CVE-2024-8318 2024-10-5 11:10 2024-09-4 Show GitHub Exploit DB Packet Storm
312497 8.8 HIGH
Network
piwebsolution product_enquiry_for_woocommerce The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untr… CWE-502
 Deserialization of Untrusted Data
CVE-2024-8922 2024-10-5 04:11 2024-09-27 Show GitHub Exploit DB Packet Storm
312498 6.1 MEDIUM
Network
stellarwp the_events_calendar The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and ou… CWE-79
Cross-site Scripting
CVE-2024-6931 2024-10-5 04:08 2024-09-27 Show GitHub Exploit DB Packet Storm
312499 5.4 MEDIUM
Network
leap13 premium_addons_for_elementor The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, and including, 4.10.52 due to insufficient… CWE-79
Cross-site Scripting
CVE-2024-8681 2024-10-5 04:04 2024-09-27 Show GitHub Exploit DB Packet Storm
312500 5.4 MEDIUM
Network
codesupply absolute_reviews The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient i… CWE-79
Cross-site Scripting
CVE-2024-8965 2024-10-5 04:04 2024-09-27 Show GitHub Exploit DB Packet Storm