Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2371 7.8 重要
Local
LizardSystems LanSpy LizardSystemsのLanSpyにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2018-25265 2026-04-30 12:14 2026-04-22 Show GitHub Exploit DB Packet Storm
2372 5.5 警告
Local
Angry IP Scanner Angry IP Scanner Angry IP Scannerにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2018-25266 2026-04-30 12:14 2026-04-22 Show GitHub Exploit DB Packet Storm
2373 7.8 重要
Local
LizardSystems LanSpy LizardSystemsのLanSpyにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2018-25268 2026-04-30 12:14 2026-04-22 Show GitHub Exploit DB Packet Storm
2374 5.5 警告
Local
Helios Textpad HeliosのTextpadにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2018-25271 2026-04-30 12:14 2026-04-22 Show GitHub Exploit DB Packet Storm
2375 4.8 警告
Network
IBM Guardium Key Lifecycle Manager IBMのGuardium Key Lifecycle Managerにおける権限管理に関する脆弱性 CWE-269
CWE-noinfo
CVE-2026-1726 2026-04-30 12:14 2026-04-23 Show GitHub Exploit DB Packet Storm
2376 9.9 緊急
Network
マイクロソフト Azure IOT Central Azure IoT Central の特権昇格の脆弱性 CWE-200
情報漏えい
CVE-2026-21515 2026-04-30 12:14 2026-04-24 Show GitHub Exploit DB Packet Storm
2377 4.8 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23752 2026-04-30 12:14 2026-04-20 Show GitHub Exploit DB Packet Storm
2378 4.8 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23753 2026-04-30 12:14 2026-04-20 Show GitHub Exploit DB Packet Storm
2379 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23756 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
2380 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23757 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313891 8.1 HIGH
Network
zyxel zld_firmware A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) s… CWE-78
OS Command 
CVE-2024-42057 2024-09-5 23:40 2024-09-3 Show GitHub Exploit DB Packet Storm
313892 6.1 MEDIUM
Network
semtekyazilim semtek_sempos Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects… CWE-79
Cross-site Scripting
CVE-2024-7077 2024-09-5 23:39 2024-09-5 Show GitHub Exploit DB Packet Storm
313893 9.8 CRITICAL
Network
semtekyazilim semtek_sempos Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This issue a… CWE-89
SQL Injection
CVE-2024-7076 2024-09-5 23:39 2024-09-5 Show GitHub Exploit DB Packet Storm
313894 7.5 HIGH
Network
zyxel zld_firmware A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware ver… CWE-476
 NULL Pointer Dereference
CVE-2024-42058 2024-09-5 23:39 2024-09-3 Show GitHub Exploit DB Packet Storm
313895 4.3 MEDIUM
Network
discourse discourse_calendar discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious ac… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2024-21658 2024-09-5 23:39 2024-08-31 Show GitHub Exploit DB Packet Storm
313896 5.4 MEDIUM
Network
azurecurve toggle_show\/hide Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Tog… CWE-79
Cross-site Scripting
CVE-2024-43961 2024-09-5 23:39 2024-08-30 Show GitHub Exploit DB Packet Storm
313897 9.8 CRITICAL
Network
semtekyazilim semtek_sempos Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue affects… CWE-89
SQL Injection
CVE-2024-7078 2024-09-5 23:38 2024-09-5 Show GitHub Exploit DB Packet Storm
313898 7.2 HIGH
Network
zyxel zld_firmware A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series… CWE-78
OS Command 
CVE-2024-42059 2024-09-5 23:38 2024-09-3 Show GitHub Exploit DB Packet Storm
313899 7.2 HIGH
Network
zyxel zld_firmware A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series… CWE-78
OS Command 
CVE-2024-42060 2024-09-5 23:37 2024-09-3 Show GitHub Exploit DB Packet Storm
313900 - - - Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. - CVE-2024-45692 2024-09-5 23:35 2024-09-5 Show GitHub Exploit DB Packet Storm