Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2791 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-31430 2026-05-25 10:23 2026-04-20 Show GitHub Exploit DB Packet Storm
2792 8.8 重要
Network
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-31432 2026-05-25 10:23 2026-04-22 Show GitHub Exploit DB Packet Storm
2793 4.3 警告
Network
GLPI-PROJECT.ORG GLPI GLPI-PROJECT.ORGのGLPIにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-32312 2026-05-25 10:23 2026-05-19 Show GitHub Exploit DB Packet Storm
2794 7.8 重要
Local
mullvad mullvad vpn mullvadのmullvad vpnにおける複数の脆弱性 CWE-269
CWE-345
CWE-427
CWE-noinfo
CVE-2026-32323 2026-05-25 10:23 2026-05-19 Show GitHub Exploit DB Packet Storm
2795 6.5 警告
Network
Faraday Project Faraday Faraday ProjectのFaradayにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-33637 2026-05-25 10:22 2026-05-19 Show GitHub Exploit DB Packet Storm
2796 8.8 重要
Local
FreeBSD FreeBSD FreeBSDにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-39461 2026-05-25 10:22 2026-05-21 Show GitHub Exploit DB Packet Storm
2797 6.5 警告
Network
plane plane planeにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-40102 2026-05-25 10:22 2026-05-20 Show GitHub Exploit DB Packet Storm
2798 7.5 重要
Network
マイクロソフト Microsoft Entra ID Microsoft Entra ID のスプーフィングの脆弱性 CWE-200
情報漏えい
CVE-2026-40379 2026-05-25 10:22 2026-05-12 Show GitHub Exploit DB Packet Storm
2799 4.3 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-4055 2026-05-25 10:22 2026-05-21 Show GitHub Exploit DB Packet Storm
2800 7.8 重要
Local
Samba Project rsync Samba Projectのrsyncにおけるレングスパラメーターの不整合による処理に関する脆弱性 CWE-130
レングスパラメーターの不整合による不適切な処理
CVE-2026-41035 2026-05-25 10:22 2026-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318601 5.4 MEDIUM
Network
connekthq ajax_load_more The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to in… CWE-79
Cross-site Scripting
CVE-2024-8505 2024-10-8 04:26 2024-10-2 Show GitHub Exploit DB Packet Storm
318602 6.1 MEDIUM
Network
goldplugins custom_banners The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3… CWE-79
Cross-site Scripting
CVE-2024-8799 2024-10-8 04:22 2024-10-1 Show GitHub Exploit DB Packet Storm
318603 8.8 HIGH
Network
plugingarden wp_easy_gallery The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient e… CWE-89
SQL Injection
CVE-2024-9018 2024-10-8 04:20 2024-10-1 Show GitHub Exploit DB Packet Storm
318604 5.0 MEDIUM
Network
openstack
redhat
heat
openstack_platform
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and th… NVD-CWE-noinfo
CVE-2024-7319 2024-10-8 04:15 2024-08-3 Show GitHub Exploit DB Packet Storm
318605 5.4 MEDIUM
Network
librenms librenms LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject… CWE-79
Cross-site Scripting
CVE-2024-47527 2024-10-8 04:08 2024-10-2 Show GitHub Exploit DB Packet Storm
318606 5.4 MEDIUM
Network
librenms librenms LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitra… CWE-79
Cross-site Scripting
CVE-2024-47525 2024-10-8 04:08 2024-10-2 Show GitHub Exploit DB Packet Storm
318607 5.4 MEDIUM
Network
librenms librenms LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject ar… CWE-79
Cross-site Scripting
CVE-2024-47523 2024-10-8 04:07 2024-10-2 Show GitHub Exploit DB Packet Storm
318608 9.8 CRITICAL
Network
definetlynotai logicytics Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2. CWE-78
OS Command 
CVE-2024-47608 2024-10-8 03:51 2024-10-2 Show GitHub Exploit DB Packet Storm
318609 6.1 MEDIUM
Network
contempo pdf_image_generator The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and includi… CWE-79
Cross-site Scripting
CVE-2024-9241 2024-10-8 03:51 2024-10-1 Show GitHub Exploit DB Packet Storm
318610 9.8 CRITICAL
Network
coderevolution echo_rss_feed_post_generator The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles t… NVD-CWE-noinfo
CVE-2024-9265 2024-10-8 03:48 2024-10-1 Show GitHub Exploit DB Packet Storm