Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2361 6.7 警告
Local
メディアテック MT8781 Firmware
MT8775 Firmware
MT6765 ファームウェア
MT6789 Firmware
MT8367 Firmware
MT6897 Firmware
MT8796 Firmware
MT6768 ファームウェア
MT6877&nb…
メディアテックのMT6765 ファームウェア等の複数製品における不十分なパーミッションまたは特権の不適切な処理に関する脆弱性 CWE-280
権限管理不備
CVE-2026-20448 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
2362 6.5 警告
Adjacent
メディアテック MT6761 ファームウェア
MT6835 Firmware
MT6858 Firmware
MT8795T Firmware
MT8797 Firmware
MT6855 Firmware
MT6880 Firmware
MT8755 Firmware
MT8668&…
メディアテックのMT2735 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-20449 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
2363 6.5 警告
Adjacent
メディアテック MT6835 Firmware
MT6858 Firmware
MT8795T Firmware
MT8797 Firmware
MT6855 Firmware
MT6880 Firmware
MT8755 Firmware
MT8668 Firmware
MT8678…
メディアテックのMT2735 ファームウェア等の複数製品における到達可能なアサーションに関する脆弱性 CWE-617
到達可能なアサーション
CVE-2026-20450 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
2364 6.7 警告
Local
メディアテック MT8186 Firmware
MT8395 Firmware
MT8678 Firmware
MT8775 Firmware
MT8781 Firmware
MT6985 Firmware
MT8188 Firmware
MT8196 Firmware
MT8367&…
メディアテックのMT2718 Firmware等の複数製品における型の取り違えに関する脆弱性 CWE-843
型の取り違え
CVE-2026-20451 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
2365 7.8 重要
Local
クアルコム QCA6574 ファームウェア
SM6650P ファームウェア
QXM1086 Firmware
SA8150P ファームウェア
QXM1096 Firmware
snapdragon 8 gen 2 mobile ファームウェア
qca6688aq …
クアルコムのAR8031 ファームウェア等の複数製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-24082 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
2366 8.8 重要
Network
RedisTimeSeries RedisTimeSeries RedisTimeSeriesにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-25588 2026-05-8 12:10 2026-05-5 Show GitHub Exploit DB Packet Storm
2367 8.8 重要
Network
RedisBloom RedisBloom RedisBloomにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-25589 2026-05-8 12:10 2026-05-5 Show GitHub Exploit DB Packet Storm
2368 7.8 重要
Local
マイクロソフト Microsoft HPC Pack Microsoft のハイ パフォーマンス コンピューティング (HPC) パックの特権昇格の脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-32184 2026-05-8 12:10 2026-04-14 Show GitHub Exploit DB Packet Storm
2369 7.5 重要
Network
マイクロソフト Microsoft Visual Studio 2026
visual studio 2022
.NET
.NET および Visual Studio のサービス拒否の脆弱性 CWE-121
CWE-20
CVE-2026-32203 2026-05-8 12:10 2026-04-14 Show GitHub Exploit DB Packet Storm
2370 4.7 警告
Network
Macaron project Macaron オラクルのMacaronにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-35253 2026-05-8 12:10 2026-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312921 4.3 MEDIUM
Network
cilium cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoute… CWE-436
 Interpretation Conflict
CVE-2024-42487 2024-10-1 03:31 2024-08-16 Show GitHub Exploit DB Packet Storm
312922 8.8 HIGH
Network
lobehub lobe_chat Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-47066 2024-10-1 03:03 2024-09-24 Show GitHub Exploit DB Packet Storm
312923 5.9 MEDIUM
Network
moxa mxview_one This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbi… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-6787 2024-10-1 03:02 2024-09-21 Show GitHub Exploit DB Packet Storm
312924 6.1 MEDIUM
Network
rws multitrans An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent … CWE-79
Cross-site Scripting
CVE-2024-43025 2024-10-1 02:51 2024-09-19 Show GitHub Exploit DB Packet Storm
312925 5.3 MEDIUM
Network
coffee2code remember_me_controls The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php … CWE-209
Information Exposure Through an Error Message
CVE-2024-7415 2024-10-1 02:46 2024-09-6 Show GitHub Exploit DB Packet Storm
312926 8.2 HIGH
Network
scriptcase scriptcase Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnera… CWE-79
Cross-site Scripting
CVE-2024-8942 2024-10-1 02:39 2024-09-25 Show GitHub Exploit DB Packet Storm
312927 7.5 HIGH
Network
linuxptp_project linuxptp An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function NVD-CWE-noinfo
CVE-2024-42861 2024-10-1 02:35 2024-09-24 Show GitHub Exploit DB Packet Storm
312928 6.1 MEDIUM
Network
flowiseai embed
flowise
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. CWE-79
Cross-site Scripting
CVE-2024-9148 2024-10-1 02:34 2024-09-25 Show GitHub Exploit DB Packet Storm
312929 5.4 MEDIUM
Network
concretecms concrete_cms Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users … CWE-79
Cross-site Scripting
CVE-2024-7398 2024-10-1 01:12 2024-09-25 Show GitHub Exploit DB Packet Storm
312930 4.8 MEDIUM
Network
concretecms concrete_cms Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete C… CWE-79
Cross-site Scripting
CVE-2024-8291 2024-10-1 00:59 2024-09-25 Show GitHub Exploit DB Packet Storm