Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2391 7.5 重要
Network
UnJS Team defu UnJS Teamのdefuにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-35209 2026-04-30 12:13 2026-04-6 Show GitHub Exploit DB Packet Storm
2392 7.5 重要
Network
オラクル Oracle Financial Services Transaction Filtering オラクルのOracle Financial Services Transaction Filteringにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-35231 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
2393 6.3 警告
Local
Flatpak XDG Desktop Portal (xdg-desktop-portal) FlatpakのXDG Desktop Portal (xdg-desktop-portal)におけるUNIX Symbolic Link のフォローに関する脆弱性 CWE-61
UNIX Symbolic Link のフォロー
CVE-2026-40354 2026-04-30 12:13 2026-04-11 Show GitHub Exploit DB Packet Storm
2394 5.3 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40448 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
2395 6.6 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40449 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
2396 6.6 警告
Local
Veeam one サムスンのOneにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-40450 2026-04-30 12:13 2026-04-22 Show GitHub Exploit DB Packet Storm
2397 8.2 重要
Network
UltraDAG UltraDAG UltraDAGにおける複数の脆弱性 CWE-460
CWE-696
CVE-2026-40583 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
2398 7.5 重要
Network
RansomLook RansomLook RansomLookにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-40584 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
2399 5.6 警告
Local
Home Assistant Ecosystem Home Assistant Command-line Interface (hass-cli) Home Assistant EcosystemのHome Assistant Command-line Interface (hass-cli)における複数の脆弱性 CWE-1336
CWE-94
CVE-2026-40602 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
2400 5.5 警告
Local
Dayuan Jiang (DayuanJiang) Next AI Draw.io Dayuan Jiang (DayuanJiang)のNext AI Draw.ioにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-40608 2026-04-30 12:12 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313791 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: io_uring: fix error pbuf checking Syz reports a problem, which boils down to NULL vs IS_ERR inconsistent error handling in io_all… CWE-476
 NULL Pointer Dereference
CVE-2024-42254 2024-09-6 22:40 2024-08-8 Show GitHub Exploit DB Packet Storm
313792 4.7 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race Ensure that `i2c_lock' is held when setting interrupt latch and mask in pca95… CWE-667
 Improper Locking
CVE-2024-42253 2024-09-6 22:38 2024-08-8 Show GitHub Exploit DB Packet Storm
313793 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: closures: Change BUG_ON() to WARN_ON() If a BUG_ON() can be hit in the wild, it shouldn't be a BUG_ON() For reference, this has … CWE-617
 Reachable Assertion
CVE-2024-42252 2024-09-6 22:37 2024-08-8 Show GitHub Exploit DB Packet Storm
313794 9.1 CRITICAL
Network
huawei emui
harmonyos
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. CWE-22
Path Traversal
CVE-2024-45443 2024-09-6 22:33 2024-09-4 Show GitHub Exploit DB Packet Storm
313795 4.3 MEDIUM
Network
salesagility suitecrm SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Ver… NVD-CWE-Other
CVE-2024-45392 2024-09-6 22:24 2024-09-6 Show GitHub Exploit DB Packet Storm
313796 6.1 MEDIUM
Network
angeljudesuarez event_management_system Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php. CWE-79
Cross-site Scripting
CVE-2024-44728 2024-09-6 22:23 2024-09-6 Show GitHub Exploit DB Packet Storm
313797 6.1 MEDIUM
Network
1e platform The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. … CWE-601
Open Redirect
CVE-2024-7211 2024-09-6 22:23 2024-08-2 Show GitHub Exploit DB Packet Storm
313798 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: page_ref: remove folio_try_get_rcu() The below bug was reported on a non-SMP kernel: [ 275.267158][ T4335] ------------[ cu… CWE-617
 Reachable Assertion
CVE-2024-42251 2024-09-6 22:21 2024-08-8 Show GitHub Exploit DB Packet Storm
313799 9.8 CRITICAL
Network
angeljudesuarez event_management_system Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php. CWE-89
SQL Injection
CVE-2024-44727 2024-09-6 22:15 2024-09-6 Show GitHub Exploit DB Packet Storm
313800 9.1 CRITICAL
Network
mindsdb mindsdb MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-24759 2024-09-6 22:06 2024-09-6 Show GitHub Exploit DB Packet Storm