Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230771 7.8 危険 リアルネットワークス - RealNetworks RealPlayer におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2497 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230772 7.5 危険 postnuke software foundation - PostNuke 用の v4bJournal モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2492 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230773 7.2 危険 VMware - EMC VMware Workstation などの PIIX4 電源管理サブシステムにおける任意のメモリ領域に書き込まれる脆弱性 - CVE-2007-2491 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230774 7.5 危険 ruben boelinger - WordPress 用の myflash プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2485 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230775 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2484 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230776 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2483 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230777 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2482 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230778 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインの wordtube-button.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2481 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230779 7.5 危険 turnkey web tools - Turnkey Web Tools SunShop Shopping Cart における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2474 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
230780 4.3 警告 sendcard - Sendcard の sendcard.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2472 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1741 - - - In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) in… - CVE-2026-43476 2026-05-14 01:16 2026-05-14 Show GitHub Exploit DB Packet Storm
1742 5.4 MEDIUM
Network
openedx openedx Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags … CWE-79
Cross-site Scripting
CVE-2026-42857 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1743 - - - Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/acco… CWE-269
CWE-434
 Improper Privilege Management
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-42844 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1744 8.8 HIGH
Local
- - Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by s… CWE-15
CWE-269
CWE-732
 External Control of System or Configuration Setting
 Improper Privilege Management
 Incorrect Permission Assignment for Critical Resource
CVE-2026-41489 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1745 - - - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-39806 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1746 - - - Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-39803 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1747 9.8 CRITICAL
Network
- - The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the un… CWE-88
Argument Injection
CVE-2026-31230 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1748 9.8 CRITICAL
Network
- - The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights f… CWE-502
 Deserialization of Untrusted Data
CVE-2026-31229 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1749 - - - Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review … CWE-863
 Incorrect Authorization
CVE-2026-2725 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1750 9.8 CRITICAL
Network
- - An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page. CWE-94
Code Injection
CVE-2025-65719 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm