Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 2:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2401 9.1 緊急
Network
rti RTI Connext Professional rtiのRTI Connext ProfessionalにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2025-14543 2026-05-7 11:29 2026-04-30 Show GitHub Exploit DB Packet Storm
2402 7.5 重要
Network
XWiki CryptPad XWikiのCryptPadにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-51846 2026-05-7 11:29 2026-04-30 Show GitHub Exploit DB Packet Storm
2403 6.4 警告
Local
レッドハット process automation manager レッドハットのprocess automation managerにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-58713 2026-05-7 11:29 2026-04-8 Show GitHub Exploit DB Packet Storm
2404 4.8 警告
Network
GNU Project GNU Wget2 GNU ProjectのGNU Wget2における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-1858 2026-05-7 11:28 2026-04-29 Show GitHub Exploit DB Packet Storm
2405 6.5 警告
Adjacent
シスコシステムズ Cisco Firepower Threat Defense ソフトウェア
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における範囲外のポインタオフセットの使用に関する脆弱性 CWE-823
範囲外のポインタオフセットの使用
CVE-2026-20022 2026-05-7 11:28 2026-03-4 Show GitHub Exploit DB Packet Storm
2406 6.5 警告
Adjacent
シスコシステムズ Cisco Firepower Threat Defense ソフトウェア
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-20023 2026-05-7 11:28 2026-03-4 Show GitHub Exploit DB Packet Storm
2407 5.7 警告
Adjacent
シスコシステムズ Cisco Firepower Threat Defense ソフトウェア
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2026-20024 2026-05-7 11:28 2026-03-4 Show GitHub Exploit DB Packet Storm
2408 8.6 重要
Network
シスコシステムズ Adaptive Security Appliance (ASA) Software シスコシステムズのAdaptive Security Appliance (ASA) Softwareにおける有効なライフタイム後のリソースの解放の欠如に関する脆弱性 CWE-772
有効なライフタイム後のリソースの解放の欠如
CVE-2026-20082 2026-05-7 11:28 2026-03-4 Show GitHub Exploit DB Packet Storm
2409 5 警告
Network
Cloud Foundry, Inc. routing release
cf-deployment
Cloud Foundry, Inc.のCf-deployment等の複数製品における意図するエンドポイントとの通信チャネルの制限に関する脆弱性 CWE-923
意図するエンドポイントとの通信チャネルの不適切な制限
CVE-2026-22726 2026-05-7 11:28 2026-05-1 Show GitHub Exploit DB Packet Storm
2410 6.5 警告
Network
VMware Spring Framework VMwareのSpring Frameworkにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-22740 2026-05-7 11:28 2026-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313451 4.8 MEDIUM
Network
mailcow mailcow\ mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is ex… CWE-79
Cross-site Scripting
CVE-2024-41960 2024-09-20 05:01 2024-08-6 Show GitHub Exploit DB Packet Storm
313452 6.1 MEDIUM
Network
nuxt nuxt Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly … CWE-79
Cross-site Scripting
CVE-2024-34343 2024-09-20 04:57 2024-08-6 Show GitHub Exploit DB Packet Storm
313453 6.5 MEDIUM
Network
lunary lunary An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invit… NVD-CWE-Other
CVE-2024-6087 2024-09-20 04:32 2024-09-14 Show GitHub Exploit DB Packet Storm
313454 3.9 LOW
Physics
redhat
opensc_project
enterprise_linux
opensc
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When … CWE-120
Classic Buffer Overflow
CVE-2024-45620 2024-09-20 04:21 2024-09-4 Show GitHub Exploit DB Packet Storm
313455 6.5 MEDIUM
Network
eaton foreseer_electrical_power_monitoring_system The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the l… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2024-31416 2024-09-20 04:06 2024-09-14 Show GitHub Exploit DB Packet Storm
313456 8.1 HIGH
Network
eaton foreseer_electrical_power_monitoring_system The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to… CWE-522
 Insufficiently Protected Credentials
CVE-2024-31415 2024-09-20 03:50 2024-09-14 Show GitHub Exploit DB Packet Storm
313457 6.1 MEDIUM
Network
eaton foreseer_electrical_power_monitoring_system The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sa… CWE-79
Cross-site Scripting
CVE-2024-31414 2024-09-20 03:48 2024-09-14 Show GitHub Exploit DB Packet Storm
313458 8.1 HIGH
Network
lunary lunary A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create pro… CWE-352
 Origin Validation Error
CVE-2024-6862 2024-09-20 03:37 2024-09-14 Show GitHub Exploit DB Packet Storm
313459 6.5 MEDIUM
Network
lunary lunary An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access righ… CWE-1220
 Insufficient Granularity of Access Control
CVE-2024-6867 2024-09-20 03:28 2024-09-14 Show GitHub Exploit DB Packet Storm
313460 9.8 CRITICAL
Network
arm mbed_tls An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in… CWE-295
Improper Certificate Validation 
CVE-2024-45159 2024-09-20 03:26 2024-09-6 Show GitHub Exploit DB Packet Storm