Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 12:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2701 5.3 警告
Network
オラクル Oracle GraalVM for JDK
Oracle GraalVM
JRE
JDK
オラクルのOracle GraalVM等の複数製品におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-22021 2026-04-28 10:13 2026-04-21 Show GitHub Exploit DB Packet Storm
2702 8.1 重要
Network
Apache Software Foundation Apache DolphinScheduler Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-23902 2026-04-28 10:13 2026-04-24 Show GitHub Exploit DB Packet Storm
2703 7.7 重要
Network
neutrinolabs xrdp neutrinolabsのxrdpにおけるデータの整合性検証不備に関する脆弱性 CWE-354
データの整合性検証不備
CVE-2026-32105 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2704 8.8 重要
Local
neutrinolabs xrdp neutrinolabsのxrdpにおける削除された特権に対する不適切なチェックに関する脆弱性 CWE-273
削除された特権に対する不適切なチェック
CVE-2026-32107 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2705 8.1 重要
Network
neutrinolabs xrdp neutrinolabsのxrdpにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-32623 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2706 6.5 警告
Network
neutrinolabs xrdp neutrinolabsのxrdpにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-32624 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2707 6.3 警告
Network
neutrinolabs xrdp neutrinolabsのxrdpにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-33145 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2708 9.1 緊急
Network
neutrinolabs xrdp neutrinolabsのxrdpにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-33516 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2709 9.1 緊急
Network
neutrinolabs xrdp neutrinolabsのxrdpにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-33689 2026-04-28 10:13 2026-04-17 Show GitHub Exploit DB Packet Storm
2710 2.9
Local
オラクル Oracle GraalVM for JDK
Oracle GraalVM
JRE
JDK
オラクルのOracle GraalVM等の複数製品における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-34268 2026-04-28 10:13 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314511 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516… CWE-89
SQL Injection
CVE-2024-36515 2024-08-27 22:28 2024-08-23 Show GitHub Exploit DB Packet Storm
314512 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. CWE-89
SQL Injection
CVE-2024-36514 2024-08-27 22:28 2024-08-23 Show GitHub Exploit DB Packet Storm
314513 9.8 CRITICAL
Network
janobe e-commerce_system A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipu… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-8089 2024-08-27 22:21 2024-08-23 Show GitHub Exploit DB Packet Storm
314514 9.8 CRITICAL
Network
janobe e-commerce_system A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation of the… CWE-89
SQL Injection
CVE-2024-8087 2024-08-27 22:19 2024-08-23 Show GitHub Exploit DB Packet Storm
314515 9.8 CRITICAL
Network
janobe e-commerce_system A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admi… CWE-89
SQL Injection
CVE-2024-8086 2024-08-27 22:17 2024-08-23 Show GitHub Exploit DB Packet Storm
314516 4.9 MEDIUM
Network
ruijie eg2000k_firmware A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknown code of the file /tool/index.php?c=download&a=save. The manipulation of the a… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-8166 2024-08-27 22:03 2024-08-27 Show GitHub Exploit DB Packet Storm
314517 - - - Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Com… - CVE-2024-43806 2024-08-27 22:02 2024-08-27 Show GitHub Exploit DB Packet Storm
314518 6.4 MEDIUM
Network
- - The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the Post Grid widget in all versions up to, and … - CVE-2024-7791 2024-08-27 22:01 2024-08-27 Show GitHub Exploit DB Packet Storm
314519 - - - Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL control… - CVE-2024-45036 2024-08-27 22:01 2024-08-27 Show GitHub Exploit DB Packet Storm
314520 - - - Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to set credentials, which allows any unaut… - CVE-2024-43798 2024-08-27 22:01 2024-08-27 Show GitHub Exploit DB Packet Storm