Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2251 8.8 重要
Network
langflow langflow
Langflow-base
langflowのLangflow-base等の複数製品における複数の脆弱性 CWE-639
CWE-862
CVE-2026-34046 2026-05-12 10:19 2026-03-27 Show GitHub Exploit DB Packet Storm
2252 7.5 重要
Network
Gazelle project Gazelle KazeburoのGazelleにおけるHTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2026-40562 2026-05-12 10:19 2026-05-6 Show GitHub Exploit DB Packet Storm
2253 5.3 警告
Network
opentelemetry OpenTelemetry.Exporter.Zipkin opentelemetryのOpenTelemetry.Exporter.Zipkinにおける複数の脆弱性 CWE-400
CWE-770
CVE-2026-41310 2026-05-12 10:19 2026-05-6 Show GitHub Exploit DB Packet Storm
2254 7.5 重要
Network
uuidjs uuid uuidjsのuuidにおける複数の脆弱性 CWE-787
CWE-823
CVE-2026-41907 2026-05-12 10:19 2026-04-24 Show GitHub Exploit DB Packet Storm
2255 7.5 重要
Network
Amazon.com, Inc. Bedrock Agentcore Starter Toolkit Amazon.com, Inc.のBedrock Agentcore Starter Toolkitにおける複数の脆弱性 CWE-283
CWE-340
CVE-2026-4269 2026-05-12 10:19 2026-03-16 Show GitHub Exploit DB Packet Storm
2256 7.5 重要
Network
VEGA VEGAPULS 6X Firmware VEGAのVEGAPULS 6X Firmwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-3323 2026-05-12 10:19 2026-04-28 Show GitHub Exploit DB Packet Storm
2257 3.3
Local
ちとらソフト Lhaz+
Lhaz
LhazおよびLhaz+におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41530 2026-05-11 17:15 2026-05-11 Show GitHub Exploit DB Packet Storm
2258 - - Apache Software Foundation Apache HTTP Server Apache HTTP Server 2.4における複数の脆弱性に対するアップデート(2026年5月) - CVE-2026-23918
CVE-2026-24072
CVE-2026-28780
CVE-2026-29168
CVE-2026-29169
CVE-2026-33006
CVE-2026-33007
CVE-2026-33523
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059
2026-05-11 16:29 2026-05-8 Show GitHub Exploit DB Packet Storm
2259 - - (複数のベンダ) (複数の製品) CISA ICS Advisory / ICS Medical Advisory(2026年05月07日) - - 2026-05-11 16:29 2026-05-8 Show GitHub Exploit DB Packet Storm
2260 7.2 重要
Network
株式会社GROWI GROWI GROWIにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41951 2026-05-11 15:29 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2091 7.3 HIGH
Network
- - A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9470 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2092 3.5 LOW
Network
- - A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-9471 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2093 6.3 MEDIUM
Network
- - A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src… CWE-22
Path Traversal
CVE-2026-9472 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2094 7.3 HIGH
Network
- - A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9474 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2095 9.8 CRITICAL
Network
- - A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interfa… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-9476 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2096 9.8 CRITICAL
Network
- - A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interf… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-9477 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2097 9.8 CRITICAL
Network
- - A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-9478 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2098 6.3 MEDIUM
Network
- - A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deseriali… CWE-20
CWE-502
 Improper Input Validation 
 Deserialization of Untrusted Data
CVE-2026-9497 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2099 6.3 MEDIUM
Network
- - A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument De… CWE-791
CWE-1336
 Incomplete Filtering of Special Elements
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-9498 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm
2100 3.3 LOW
Local
- - A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipul… CWE-617
 Reachable Assertion
CVE-2026-9501 2026-05-27 04:54 2026-05-26 Show GitHub Exploit DB Packet Storm