Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2821 9.6 緊急
Network
langflow langflow langflowにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-42048 2026-05-15 11:00 2026-05-12 Show GitHub Exploit DB Packet Storm
2822 5.5 警告
Local
ImageMagick ImageMagick ImageMagickにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-42050 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
2823 8.1 重要
Network
- OpenC3のOpenC3 COSMOSにおける不要な特権による実行に関する脆弱性 CWE-250
不要な特権による実行
CVE-2026-42088 2026-05-15 11:00 2026-05-4 Show GitHub Exploit DB Packet Storm
2824 8.8 重要
Network
litellm litellm LiteLLMにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-42203 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
2825 9.1 緊急
Network
axios project axios axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42264 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
2826 5.7 警告
Network
Kimai project kimai Kimai projectのKimaiにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2026-42267 2026-05-15 11:00 2026-05-8 Show GitHub Exploit DB Packet Storm
2827 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-42499 2026-05-15 11:00 2026-05-7 Show GitHub Exploit DB Packet Storm
2828 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおけるデジタル署名の検証に関する脆弱性 CWE-347
デジタル署名の不適切な検証
CVE-2026-42501 2026-05-15 11:00 2026-05-7 Show GitHub Exploit DB Packet Storm
2829 9.1 緊急
Network
Grav CMS grav Grav CMSのgravにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-42608 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
2830 5.4 警告
Network
Open edX openedx Open edXのopenedxにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42857 2026-05-15 11:00 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314181 6.1 MEDIUM
Network
phpgurukul car_rental_portal A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search.php. The manipulation of the argument s… CWE-79
Cross-site Scripting
CVE-2024-10701 2024-11-6 01:52 2024-11-3 Show GitHub Exploit DB Packet Storm
314182 6.5 MEDIUM
Network
cert vince VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. CWE-276
Incorrect Default Permissions 
CVE-2024-10469 2024-11-6 01:51 2024-10-29 Show GitHub Exploit DB Packet Storm
314183 4.8 MEDIUM
Adjacent
argo_workflows_project argo_workflows Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controll… CWE-362
CWE-1108
Race Condition
 Excessive Reliance on Global Variables
CVE-2024-47827 2024-11-6 01:50 2024-10-29 Show GitHub Exploit DB Packet Storm
314184 7.5 HIGH
Network
squid-cache squid Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resour… NVD-CWE-noinfo
CVE-2024-45802 2024-11-6 01:45 2024-10-29 Show GitHub Exploit DB Packet Storm
314185 7.5 HIGH
Network
ruby-lang rexml REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). … CWE-1333
 Inefficient Regular Expression Complexity
CVE-2024-49761 2024-11-6 01:41 2024-10-29 Show GitHub Exploit DB Packet Storm
314186 7.5 HIGH
Network
ibm cics_transaction_gateway IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retr… CWE-522
 Insufficiently Protected Credentials
CVE-2023-50310 2024-11-6 01:40 2024-10-23 Show GitHub Exploit DB Packet Storm
314187 - - - Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via… - CVE-2024-52030 2024-11-6 01:35 2024-11-6 Show GitHub Exploit DB Packet Storm
314188 - - - Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via … - CVE-2024-52029 2024-11-6 01:35 2024-11-6 Show GitHub Exploit DB Packet Storm
314189 - - - Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a … - CVE-2024-52028 2024-11-6 01:35 2024-11-6 Show GitHub Exploit DB Packet Storm
314190 - - - Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to … - CVE-2024-52026 2024-11-6 01:35 2024-11-6 Show GitHub Exploit DB Packet Storm