Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2151 4.9 警告
Network
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-31927 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2152 7.7 重要
Local
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおけるハードコードされた暗号鍵の使用に関する脆弱性 CWE-321
ハードコードされた暗号鍵の使用
CVE-2026-32324 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2153 5.3 警告
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-32648 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2154 7.5 重要
Network
Anviz Global Crosschex Standard Anviz GlobalのCrosschex Standardにおけるアルゴリズムのダウングレードに関する脆弱性 CWE-757
アルゴリズムのダウングレード
CVE-2026-32650 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2155 5.3 警告
Network
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33093 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2156 6.5 警告
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品における重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2026-33569 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2157 4.3 警告
Network
SAP SAP HANA Database Explorer
SAP HANA Cockpit
SAPのSAP HANA Cockpit等の複数製品における認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-34262 2026-05-7 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
2158 5.3 警告
Network
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-35061 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2159 9.8 緊急
Network
Anviz Global Anviz CX7 Firmware
Anviz CX2 Lite Firmware
Anviz GlobalのAnviz CX2 Lite Firmware等の複数製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35546 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
2160 8.8 重要
Network
Anviz Global Anviz CX2 Lite Firmware Anviz GlobalのAnviz CX2 Lite Firmwareにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-35682 2026-05-7 11:29 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313221 - - - Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) - CVE-2024-8904 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313222 - - - Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages r… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-46982 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313223 - - - Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. … CWE-79
Cross-site Scripting
CVE-2024-45812 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313224 - - - Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow… CWE-200
CWE-284
Information Exposure
Improper Access Control
CVE-2024-45811 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313225 - - - arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution (PPE… CWE-94
CWE-20
CWE-78
Code Injection
 Improper Input Validation 
OS Command 
CVE-2024-45798 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313226 - - - Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a … - CVE-2024-42503 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313227 - - - Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underly… - CVE-2024-42502 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313228 - - - An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system… - CVE-2024-42501 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313229 - - - A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-base… CWE-400
 Uncontrolled Resource Consumption
CVE-2024-8939 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm
313230 - - - A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service. CWE-617
 Reachable Assertion
CVE-2024-8768 2024-09-20 21:30 2024-09-18 Show GitHub Exploit DB Packet Storm