Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2341 6.5 警告
Network
nginxui Nginx UI Nginx UI TeamのNginx UIにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-42223 2026-05-8 12:23 2026-05-4 Show GitHub Exploit DB Packet Storm
2342 7.5 重要
Network
n8n n8n n8nにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-42226 2026-05-8 12:23 2026-05-4 Show GitHub Exploit DB Packet Storm
2343 6.5 警告
Network
n8n n8n n8nにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-42227 2026-05-8 12:23 2026-05-4 Show GitHub Exploit DB Packet Storm
2344 6.5 警告
Network
n8n n8n n8nにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-42228 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2345 8.8 重要
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-42229 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2346 6.1 警告
Network
n8n n8n n8nにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-42230 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2347 8.8 重要
Network
n8n n8n n8nにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42231 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2348 8.8 重要
Network
n8n n8n n8nにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42232 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2349 9.8 緊急
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-42233 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
2350 8.8 重要
Network
n8n n8n n8nにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-42234 2026-05-8 12:22 2026-05-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312451 6.1 MEDIUM
Network
paloaltonetworks expedition A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a maliciou… CWE-79
Cross-site Scripting
CVE-2024-9467 2024-10-16 00:09 2024-10-10 Show GitHub Exploit DB Packet Storm
312452 7.5 HIGH
Network
sparkshop sparkshop A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. NVD-CWE-noinfo
CVE-2024-46307 2024-10-15 23:57 2024-10-10 Show GitHub Exploit DB Packet Storm
312453 7.8 HIGH
Local
progress telerik_reporting In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation. CWE-470
Unsafe Reflection
CVE-2024-8048 2024-10-15 23:56 2024-10-10 Show GitHub Exploit DB Packet Storm
312454 7.2 HIGH
Network
progress telerik_report_server In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability. CWE-470
Unsafe Reflection
CVE-2024-8015 2024-10-15 23:55 2024-10-10 Show GitHub Exploit DB Packet Storm
312455 8.8 HIGH
Network
progress telerik_reporting In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability. CWE-470
Unsafe Reflection
CVE-2024-8014 2024-10-15 23:54 2024-10-10 Show GitHub Exploit DB Packet Storm
312456 7.8 HIGH
Local
progress telerik_reporting In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements. CWE-77
Command Injection
CVE-2024-7840 2024-10-15 23:52 2024-10-10 Show GitHub Exploit DB Packet Storm
312457 6.5 MEDIUM
Network
progress telerik_reporting In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. NVD-CWE-noinfo
CVE-2024-7294 2024-10-15 23:51 2024-10-10 Show GitHub Exploit DB Packet Storm
312458 8.8 HIGH
Network
progress telerik_reporting In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements. CWE-521
Weak Password Requirements 
CVE-2024-7293 2024-10-15 23:51 2024-10-10 Show GitHub Exploit DB Packet Storm
312459 8.8 HIGH
Network
progress telerik_report_server In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2024-7292 2024-10-15 23:50 2024-10-10 Show GitHub Exploit DB Packet Storm
312460 7.5 HIGH
Network
templateinvaders ti_woocommerce_wishlist The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin… CWE-89
SQL Injection
CVE-2024-9156 2024-10-15 23:40 2024-10-10 Show GitHub Exploit DB Packet Storm