Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2871 9.8 緊急
Network
hashcat hashcat hashcatにおける境界外書き込みに関する脆弱性 CWE-787
CWE-787
CVE-2026-42484 2026-05-7 12:00 2026-05-1 Show GitHub Exploit DB Packet Storm
2872 9.1 緊急
Network
Technostrobe HI-LED-WR120-G2 Firmware TechnostrobeのHI-LED-WR120-G2 Firmwareにおける複数の脆弱性 CWE-862
CWE-863
CVE-2026-5574 2026-05-7 12:00 2026-04-5 Show GitHub Exploit DB Packet Storm
2873 7.1 重要
Local
レッドハット
Xiph.Org
Red Hat Enterprise Linux
Theora
レッドハット等の複数ベンダの製品における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-5673 2026-05-7 12:00 2026-04-6 Show GitHub Exploit DB Packet Storm
2874 9.8 緊急
Network
Sipeed Picoclaw SipeedのPicoclawにおける複数の脆弱性 CWE-74
CWE-77
CVE-2026-6987 2026-05-7 12:00 2026-04-25 Show GitHub Exploit DB Packet Storm
2875 8.8 重要
Network
Coze Coze Studio CozeのCoze Studioにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-7023 2026-05-7 12:00 2026-04-26 Show GitHub Exploit DB Packet Storm
2876 7.3 重要
Network
ShadowCloneLabs Glutamate MCP Servers ShadowCloneLabsのGlutamate MCP Serversにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-7094 2026-05-7 12:00 2026-04-27 Show GitHub Exploit DB Packet Storm
2877 5.4 警告
Network
helpy.io helpy helpy.ioのhelpyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40229 2026-05-7 12:00 2026-04-29 Show GitHub Exploit DB Packet Storm
2878 5.4 警告
Network
helpy.io helpy helpy.ioのhelpyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40230 2026-05-7 12:00 2026-04-29 Show GitHub Exploit DB Packet Storm
2879 7.5 重要
Network
Exim Development Exim Exim DevelopmentのEximにおける指定された機能の不適切な提供に関する脆弱性 CWE-684
指定された機能の不適切な提供
CVE-2026-40684 2026-05-7 12:00 2026-04-30 Show GitHub Exploit DB Packet Storm
2880 9.8 緊急
Network
Exim Development Exim Exim DevelopmentのEximにおける複数の脆弱性 CWE-684
CWE-787
CVE-2026-40685 2026-05-7 12:00 2026-04-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313241 - - - DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter. - CVE-2024-41584 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313242 - - - DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name. - CVE-2024-41583 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313243 - - - Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly i… CWE-440
 Expected Behavior Violation
CVE-2024-47762 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313244 - - - TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTT… CWE-306
Missing Authentication for Critical Function
CVE-2024-41988 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313245 - - - The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exp… CWE-352
 Origin Validation Error
CVE-2024-41987 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313246 - - - Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files. - CVE-2024-45872 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313247 - - - Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). - CVE-2024-45871 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313248 - - - NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A s… CWE-476
 NULL Pointer Dereference
CVE-2024-0125 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313249 - - - NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A succ… CWE-416
 Use After Free
CVE-2024-0124 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm
313250 - - - NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into runnin… CWE-1285
 Improper Validation of Specified Index, Position, or Offset in Input
CVE-2024-0123 2024-10-4 22:50 2024-10-4 Show GitHub Exploit DB Packet Storm