Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2201 8.8 重要
Local
アップル iOS
tvOS
watchOS
visionos
iPadOS
アップルのiPadOS等の複数製品における権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-28995 2026-05-14 10:20 2026-05-11 Show GitHub Exploit DB Packet Storm
2202 6.5 警告
Network
Gofiber Fiber GofiberのFiberにおける解釈の競合に関する脆弱性 CWE-436
解釈の競合
CVE-2026-30246 2026-05-14 10:20 2026-05-5 Show GitHub Exploit DB Packet Storm
2203 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-31784 2026-05-14 10:20 2026-05-1 Show GitHub Exploit DB Packet Storm
2204 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-31785 2026-05-14 10:20 2026-05-1 Show GitHub Exploit DB Packet Storm
2205 4.9 警告
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-33611 2026-05-14 10:20 2026-04-22 Show GitHub Exploit DB Packet Storm
2206 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおける二重解放に関する脆弱性 CWE-415
二重解放
CVE-2026-33811 2026-05-14 10:20 2026-05-7 Show GitHub Exploit DB Packet Storm
2207 7.8 重要
Local
アドビシステムズ Adobe Illustrator アドビのAdobe Illustratorにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-34661 2026-05-14 10:20 2026-05-12 Show GitHub Exploit DB Packet Storm
2208 5.5 警告
Local
アドビシステムズ Adobe Illustrator アドビのAdobe IllustratorにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-34662 2026-05-14 10:20 2026-05-12 Show GitHub Exploit DB Packet Storm
2209 5.5 警告
Local
アドビシステムズ Adobe Illustrator アドビのAdobe Illustratorにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-34663 2026-05-14 10:20 2026-05-12 Show GitHub Exploit DB Packet Storm
2210 7.8 重要
Local
アドビシステムズ Adobe Substance 3D Painter アドビのAdobe Substance 3D Painterにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-34675 2026-05-14 10:20 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311851 - - - A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions. - CVE-2024-43425 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311852 6.4 MEDIUM
Network
- - The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all v… CWE-79
Cross-site Scripting
CVE-2024-8442 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311853 - - - Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available. - CVE-2024-24914 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311854 - - - Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows l… - CVE-2024-10526 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311855 - - - Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting… CWE-79
Cross-site Scripting
CVE-2024-51989 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
311856 - - - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop Driver waits indefinitely for the fifo occupancy to go below a thre… - CVE-2024-50157 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311857 - - - Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines. - CVE-2024-10203 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311858 7.5 HIGH
Network
- - A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error… - CVE-2023-1973 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311859 - - - A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in… - CVE-2023-1932 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
311860 - - - HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cooki… - CVE-2024-30142 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm