|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 28, 2026, 2:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 2561 | 5.3 |
警告
Network |
Kazuho Oku (kazuho) | Starlet | Kazuho Oku (kazuho)のStarletにおけるHTTP リクエストスマグリングに関する脆弱性 |
CWE-444
HTTP リクエストスマグリング |
CVE-2026-40561 | 2026-05-8 12:10 | 2026-05-3 | Show | GitHub Exploit DB Packet Storm |
| 2562 | 7.5 |
重要
Network |
NERDVANA (Michael Conrad) | Crypt-SecretBuffer | NERDVANA (Michael Conrad)のCrypt-SecretBufferにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 |
CWE-208
タイミングの違いに起因する情報漏えい |
CVE-2026-5086 | 2026-05-8 12:10 | 2026-04-13 | Show | GitHub Exploit DB Packet Storm |
| 2563 | 7.5 |
重要
Network |
JDEGUEST (Jacques Deguest) | Apache::API::Password | JDEGUEST (Jacques Deguest)のApache::API::Passwordにおける暗号の脆弱な PRNG の使用に関する脆弱性 |
CWE-338
暗号における脆弱な PRNG の使用 |
CVE-2026-5088 | 2026-05-8 12:09 | 2026-04-15 | Show | GitHub Exploit DB Packet Storm |
| 2564 | 8.8 |
重要
Network |
Cerberus, LLC | Cerberus FTP Server | CerberusのCerberus FTP Serverにおける安全に保持されない継承されたパーミッションに関する脆弱性 |
CWE-278
安全に保持されない継承されたパーミッション |
CVE-2026-6265 | 2026-05-8 12:09 | 2026-04-27 | Show | GitHub Exploit DB Packet Storm |
| 2565 | 8.8 |
重要
Network |
レッドハット |
Red Hat Enterprise Linux AI InstructLab |
レッドハットのRed Hat Enterprise Linux AI等の複数製品における信頼できない制御領域からの機能の組み込みに関する脆弱性 |
CWE-829
信頼性のない制御領域からの機能の組み込み |
CVE-2026-6859 | 2026-05-8 12:09 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 2566 | 6.5 |
警告
Network |
Amazon.com, Inc. |
tuftool Amazon tough |
Amazon.com, Inc.のAmazon tough等の複数製品におけるデジタル署名の検証に関する脆弱性 |
CWE-347
デジタル署名の不適切な検証 |
CVE-2026-6966 | 2026-05-8 12:09 | 2026-04-24 | Show | GitHub Exploit DB Packet Storm |
| 2567 | 6.5 |
警告
Network |
Amazon.com, Inc. |
tuftool Amazon tough |
Amazon.com, Inc.のAmazon tough等の複数製品におけるデータの信頼性についての不十分な検証に関する脆弱性 |
CWE-345
データの信頼性についての不十分な検証 |
CVE-2026-6967 | 2026-05-8 12:09 | 2026-04-24 | Show | GitHub Exploit DB Packet Storm |
| 2568 | 6.5 |
警告
Network |
Amazon.com, Inc. |
tuftool Amazon tough |
Amazon.com, Inc.のAmazon tough等の複数製品におけるパストラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2026-6968 | 2026-05-8 12:09 | 2026-04-24 | Show | GitHub Exploit DB Packet Storm |
| 2569 | 7.5 |
重要
Network |
RRWO (Robert Rothenberg) | Text::Minify::XS | RRWO (Robert Rothenberg)のText::Minify::XSにおける複数の脆弱性 |
CWE-122 CWE-176 |
CVE-2026-7040 | 2026-05-8 12:09 | 2026-04-27 | Show | GitHub Exploit DB Packet Storm |
| 2570 | 8.4 |
重要
Local |
HMBRAND (H.Merijn Brand) | Text::CSV_XS | HMBRAND (H.Merijn Brand)のText::CSV_XSにおける複数の脆弱性 |
CWE-416 CWE-825 |
CVE-2026-7111 | 2026-05-8 12:09 | 2026-04-29 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 28, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 312711 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_server_2022 windows_server_2019 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43549 | 2024-10-18 04:51 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312712 | 7.5 |
HIGH
Network |
znuny | znuny | Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and… |
CWE-1333
Inefficient Regular Expression Complexity |
CVE-2024-48938 | 2024-10-18 04:49 | 2024-10-12 | Show | GitHub Exploit DB Packet Storm |
| 312713 | 7.4 |
HIGH
Network |
microsoft |
windows_server_2012 windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_10_1607 windows_server_2019 windows_11_21h2 win… |
Windows Secure Channel Spoofing Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43550 | 2024-10-18 04:49 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312714 | 6.1 |
MEDIUM
Network |
znuny | znuny | Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed. |
CWE-79
Cross-site Scripting |
CVE-2024-48937 | 2024-10-18 04:48 | 2024-10-12 | Show | GitHub Exploit DB Packet Storm |
| 312715 | 7.8 |
HIGH
Local |
microsoft |
windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_10_1607 windows_server_2019 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows… |
Windows Storage Elevation of Privilege Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43551 | 2024-10-18 04:48 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312716 | 7.0 |
HIGH
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_10_1607 windows_server_2019 | NT OS Kernel Elevation of Privilege Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43553 | 2024-10-18 04:47 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312717 | 7.3 |
HIGH
Local |
microsoft |
windows_server_2022_23h2 windows_11_22h2 windows_11_23h2 windows_11_24h2 |
Windows Shell Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43552 | 2024-10-18 04:47 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312718 | 5.5 |
MEDIUM
Local |
microsoft |
windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_10_1607 windows_server_2019 windows_11_21h2 windows_10_21h2 windows… |
Windows Kernel-Mode Driver Information Disclosure Vulnerability |
NVD-CWE-noinfo
|
CVE-2024-43554 | 2024-10-18 04:42 | 2024-10-9 | Show | GitHub Exploit DB Packet Storm |
| 312719 | 7.8 |
HIGH
Local |
lenovo | app_store | A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges. |
CWE-427
Uncontrolled Search Path Element |
CVE-2024-4130 | 2024-10-18 04:41 | 2024-10-12 | Show | GitHub Exploit DB Packet Storm |
| 312720 | 7.8 |
HIGH
Local |
lenovo | superfile | A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges. |
CWE-427
Uncontrolled Search Path Element |
CVE-2024-4089 | 2024-10-18 04:41 | 2024-10-12 | Show | GitHub Exploit DB Packet Storm |