Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2761 9 緊急
Network
craftycontrol crafty controller craftycontrolのcrafty controllerにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-5652 2026-04-30 12:24 2026-04-21 Show GitHub Exploit DB Packet Storm
2762 7.5 重要
Network
HashiCorp Vault HashiCorpのVaultにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-5807 2026-04-30 12:24 2026-04-17 Show GitHub Exploit DB Packet Storm
2763 7.1 重要
Local
radare radare2 radareのradare2におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-6940 2026-04-30 12:24 2026-04-23 Show GitHub Exploit DB Packet Storm
2764 7.8 重要
Local
radare radare2 radareのradare2における複数の脆弱性 CWE-22
CWE-59
CVE-2026-6941 2026-04-30 12:24 2026-04-23 Show GitHub Exploit DB Packet Storm
2765 7.5 重要
Network
Sgbett BSV Ruby SDK (bsv-sdk) SgbettのBSV Ruby SDK (bsv-sdk)における例外的な状態のチェックに関する脆弱性 CWE-754
例外的な状態における不適切なチェック
CVE-2026-40069 2026-04-30 12:18 2026-04-9 Show GitHub Exploit DB Packet Storm
2766 5.3 警告
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2026-40431 2026-04-30 12:18 2026-04-24 Show GitHub Exploit DB Packet Storm
2767 9.8 緊急
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-40620 2026-04-30 12:18 2026-04-24 Show GitHub Exploit DB Packet Storm
2768 8.1 重要
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40623 2026-04-30 12:18 2026-04-24 Show GitHub Exploit DB Packet Storm
2769 9.8 緊急
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-40630 2026-04-30 12:18 2026-04-24 Show GitHub Exploit DB Packet Storm
2770 5.3 警告
Network
opentelemetry opentelemetry
OpenTelemetry.Extensions.Propagators
Opentelemetry.api
opentelemetryのOpentelemetry.api等の複数製品における過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-40894 2026-04-30 12:18 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314031 6.5 MEDIUM
Network
digiwin easyflow_.net Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vuln… CWE-22
Path Traversal
CVE-2024-7323 2024-09-11 23:22 2024-08-2 Show GitHub Exploit DB Packet Storm
314032 9.8 CRITICAL
Network
forip administracao_pabx A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the compo… CWE-89
SQL Injection
CVE-2024-7461 2024-09-11 23:16 2024-08-5 Show GitHub Exploit DB Packet Storm
314033 - - - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. - CVE-2024-7805 2024-09-11 23:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314034 6.1 MEDIUM
Network
lang-learn-guy learning_with_texts Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can in… CWE-79
Cross-site Scripting
CVE-2024-41572 2024-09-11 23:15 2024-08-22 Show GitHub Exploit DB Packet Storm
314035 5.9 MEDIUM
Network
ibm java_sdk The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the … NVD-CWE-noinfo
CVE-2024-27267 2024-09-11 22:48 2024-08-15 Show GitHub Exploit DB Packet Storm
314036 6.5 MEDIUM
Network
qnap qts
quts_hero
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expos… CWE-22
Path Traversal
CVE-2024-21904 2024-09-11 22:40 2024-09-7 Show GitHub Exploit DB Packet Storm
314037 5.9 MEDIUM
Network
ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued b… NVD-CWE-Other
CVE-2023-50315 2024-09-11 22:38 2024-08-15 Show GitHub Exploit DB Packet Storm
314038 4.7 MEDIUM
Network
qnap qts
quts_hero
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands … CWE-78
CWE-77
OS Command 
Command Injection
CVE-2024-21903 2024-09-11 22:36 2024-09-7 Show GitHub Exploit DB Packet Storm
314039 8.8 HIGH
Network
qnap qts
quts_hero
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a net… CWE-78
OS Command 
CVE-2024-21898 2024-09-11 22:35 2024-09-7 Show GitHub Exploit DB Packet Storm
314040 5.4 MEDIUM
Network
qnap qts
quts_hero
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code… CWE-79
Cross-site Scripting
CVE-2024-21897 2024-09-11 22:34 2024-09-7 Show GitHub Exploit DB Packet Storm