Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2801 8.1 重要
Network
OpenBSD OpenSSH OpenBSDのOpenSSHにおける不適切な動作順序に関する脆弱性 CWE-696
不適切な動作順序
CVE-2026-35386 2026-04-28 10:12 2026-04-2 Show GitHub Exploit DB Packet Storm
2802 6.5 警告
Network
OpenBSD OpenSSH OpenBSDのOpenSSHにおける常に不適切な制御フローの実装に関する脆弱性 CWE-670
常に不適切な制御フローの実装
CVE-2026-35387 2026-04-28 10:12 2026-04-2 Show GitHub Exploit DB Packet Storm
2803 2.5
Local
OpenBSD OpenSSH OpenBSDのOpenSSHにおける保護されていない代替チャネルに関する脆弱性 CWE-420
保護されていない代替チャネル
CVE-2026-35388 2026-04-28 10:12 2026-04-2 Show GitHub Exploit DB Packet Storm
2804 8.8 重要
Network
neutrinolabs xrdp neutrinolabsのxrdpにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-35512 2026-04-28 10:12 2026-04-17 Show GitHub Exploit DB Packet Storm
2805 4.3 警告
Network
Apache Software Foundation Apache Airflow Apache Software FoundationのApache Airflowにおけるアクセス制御の不十分な粒度に関する脆弱性 CWE-1220
アクセス制御の不十分な粒度
CVE-2026-38743 2026-04-28 10:12 2026-04-24 Show GitHub Exploit DB Packet Storm
2806 7.7 重要
Network
Lee Peuker Movary Lee PeukerのMovaryにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-40348 2026-04-28 10:12 2026-04-18 Show GitHub Exploit DB Packet Storm
2807 8.8 重要
Network
Lee Peuker Movary Lee PeukerのMovaryにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40349 2026-04-28 10:12 2026-04-18 Show GitHub Exploit DB Packet Storm
2808 8.8 重要
Network
Lee Peuker Movary Lee PeukerのMovaryにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-40350 2026-04-28 10:12 2026-04-18 Show GitHub Exploit DB Packet Storm
2809 8.8 重要
Network
Apache Software Foundation ActiveMQ Broker
Apache ActiveMQ
Apache Software FoundationのApache ActiveMQ等の複数製品における複数の脆弱性 CWE-20
CWE-94
CVE-2026-40466 2026-04-28 10:12 2026-04-24 Show GitHub Exploit DB Packet Storm
2810 4.3 警告
Network
Apache Software Foundation Apache Airflow Apache Software FoundationのApache Airflowにおけるアクセス制御の不十分な粒度に関する脆弱性 CWE-1220
アクセス制御の不十分な粒度
CVE-2026-40690 2026-04-28 10:12 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
761 5.5 MEDIUM
Local
gpac gpac A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. … CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-8124 2026-05-15 03:02 2026-05-8 Show GitHub Exploit DB Packet Storm
762 7.5 HIGH
Network
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-35424 2026-05-15 03:02 2026-05-13 Show GitHub Exploit DB Packet Storm
763 6.5 MEDIUM
Network
8421bit miniclaw A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vulnerability is the function isPathInside of the file src/kernel.ts of the compone… CWE-22
Path Traversal
CVE-2026-8113 2026-05-15 03:02 2026-05-8 Show GitHub Exploit DB Packet Storm
764 9.8 CRITICAL
Network
yarbo lawn_mower_firmware
lawn_mower_pro_firmware
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cann… CWE-912
NVD-CWE-noinfo
 Hidden Functionality
CVE-2026-7413 2026-05-15 02:54 2026-05-8 Show GitHub Exploit DB Packet Storm
765 9.8 CRITICAL
Network
yarbo lawn_mower_firmware
lawn_mower_pro_firmware
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or r… CWE-798
 Use of Hard-coded Credentials
CVE-2026-7414 2026-05-15 02:53 2026-05-8 Show GitHub Exploit DB Packet Storm
766 7.8 HIGH
Local
microsoft windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2025
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. CWE-822
 Untrusted Pointer Dereference
CVE-2026-40369 2026-05-15 02:52 2026-05-13 Show GitHub Exploit DB Packet Storm
767 7.8 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. CWE-122
Heap-based Buffer Overflow
CVE-2026-40377 2026-05-15 02:52 2026-05-13 Show GitHub Exploit DB Packet Storm
768 9.8 CRITICAL
Network
yarbo lawn_mower_firmware
lawn_mower_pro_firmware
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetr… CWE-306
Missing Authentication for Critical Function
CVE-2026-7415 2026-05-15 02:50 2026-05-8 Show GitHub Exploit DB Packet Storm
769 6.2 MEDIUM
Physics
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. CWE-122
CWE-125
CWE-197
Heap-based Buffer Overflow
Out-of-bounds Read
 Numeric Truncation Error
CVE-2026-40380 2026-05-15 02:49 2026-05-13 Show GitHub Exploit DB Packet Storm
770 7.8 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CWE-843
Type Confusion
CVE-2026-34344 2026-05-15 02:48 2026-05-13 Show GitHub Exploit DB Packet Storm