Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2691 5.3 警告
Network
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-5772 2026-04-30 10:57 2026-04-9 Show GitHub Exploit DB Packet Storm
2692 6.5 警告
Network
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおける整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2026-5778 2026-04-30 10:57 2026-04-9 Show GitHub Exploit DB Packet Storm
2693 9.6 緊急
Network
GitHub Enterprise Server GitHubのEnterprise Serverにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-5845 2026-04-30 10:57 2026-04-21 Show GitHub Exploit DB Packet Storm
2694 8.9 重要
Network
GitHub Enterprise Server GitHubのEnterprise Serverにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-5921 2026-04-30 10:57 2026-04-21 Show GitHub Exploit DB Packet Storm
2695 7.8 重要
Local
レッドハット
gimp
Red Hat Enterprise Linux
gimp
gimp等の複数ベンダの製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-6384 2026-04-30 10:57 2026-04-15 Show GitHub Exploit DB Packet Storm
2696 7.8 重要
Local
Rapid7 Insight Agent Rapid7のInsight Agentにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-6482 2026-04-30 10:57 2026-04-17 Show GitHub Exploit DB Packet Storm
2697 8.1 重要
Network
Mozilla Foundation Mozilla Thunderbird
Mozilla Firefox
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 CWE-125
CWE-416
CWE-787
CVE-2026-6785 2026-04-30 10:57 2026-04-26 Show GitHub Exploit DB Packet Storm
2698 8.1 重要
Network
Mozilla Foundation Mozilla Thunderbird
Mozilla Firefox
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 CWE-125
CWE-416
CWE-787
CVE-2026-6786 2026-04-30 10:57 2026-04-26 Show GitHub Exploit DB Packet Storm
2699 7.8 重要
Local
IObit Malware Fighter IObitのMalware Fighterにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2016-20059 2026-04-28 10:14 2026-04-4 Show GitHub Exploit DB Packet Storm
2700 6.3 警告
Network
Apache Software Foundation Apache DolphinScheduler Apache Software FoundationのApache DolphinSchedulerにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-62233 2026-04-28 10:14 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314181 9.8 CRITICAL
Network
mozilla firefox
firefox_esr
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2… CWE-843
Type Confusion
CVE-2024-8385 2024-09-7 02:15 2024-09-3 Show GitHub Exploit DB Packet Storm
314182 9.8 CRITICAL
Network
mozilla firefox_esr
firefox
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulner… CWE-787
 Out-of-bounds Write
CVE-2024-8384 2024-09-7 02:15 2024-09-3 Show GitHub Exploit DB Packet Storm
314183 9.8 CRITICAL
Network
mozilla firefox_esr
firefox
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < … CWE-843
Type Confusion
CVE-2024-8381 2024-09-7 02:15 2024-09-3 Show GitHub Exploit DB Packet Storm
314184 10.0 CRITICAL
Network
wpindeed ultimate_membership_pro Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6. CWE-502
 Deserialization of Untrusted Data
CVE-2024-43242 2024-09-7 01:57 2024-08-20 Show GitHub Exploit DB Packet Storm
314185 7.5 HIGH
Network
raidenmaild raidenmaild Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the remote server. CWE-22
Path Traversal
CVE-2024-7693 2024-09-7 01:51 2024-08-12 Show GitHub Exploit DB Packet Storm
314186 - - - H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access… - CVE-2024-45758 2024-09-7 01:46 2024-09-7 Show GitHub Exploit DB Packet Storm
314187 - - - Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two email… - CVE-2024-25584 2024-09-7 01:46 2024-09-7 Show GitHub Exploit DB Packet Storm
314188 - - - `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a… - CVE-2024-45405 2024-09-7 01:46 2024-09-6 Show GitHub Exploit DB Packet Storm
314189 - - - Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. - CVE-2024-44739 2024-09-7 01:46 2024-09-6 Show GitHub Exploit DB Packet Storm
314190 8.8 HIGH
Network
ibm webmethods_integration IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication. NVD-CWE-Other
CVE-2024-45075 2024-09-7 01:45 2024-09-5 Show GitHub Exploit DB Packet Storm