Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2921 4.8 警告
Network
mitmproxy mitmproxy mitmproxyにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-40606 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2922 7.5 重要
Network
coturn project coturn coturn projectのcoturnにおける不正な型変換に関する脆弱性 CWE-704
不正な型変換またはキャスト
CVE-2026-40613 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2923 8.8 重要
Network
goshs goshs goshsにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40876 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2924 7.5 重要
Network
- NestJSにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-40879 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2925 7.6 重要
Network
openremote openremote openremoteにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-40882 2026-04-27 10:47 2026-04-22 Show GitHub Exploit DB Packet Storm
2926 8.3 重要
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40925 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2927 8.3 重要
Network
RustFS RustFS RustFSにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40937 2026-04-27 10:47 2026-04-22 Show GitHub Exploit DB Packet Storm
2928 7.1 重要
Network
WWBN AVideo WWBNのAVideoにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-41057 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2929 8.1 重要
Network
WWBN AVideo WWBNのAVideoにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41058 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
2930 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41060 2026-04-27 10:47 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315131 - isc
netscape
caldera
bsdi
redhat
nec
inn
news_server
openlinux
bsd_os
linux
goah_networksv
goah_intrasv
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. NVD-CWE-Other
CVE-1999-0043 2024-08-2 05:35 1996-12-4 Show GitHub Exploit DB Packet Storm
315132 - sun solaris Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka Sys… NVD-CWE-Other
CVE-1999-1588 2024-08-2 04:35 1999-12-31 Show GitHub Exploit DB Packet Storm
315133 - ssh ssh Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. NVD-CWE-Other
CVE-1999-0013 2024-08-2 04:35 1998-01-22 Show GitHub Exploit DB Packet Storm
315134 - - - The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks - CVE-2024-6412 2024-08-2 03:35 2024-07-31 Show GitHub Exploit DB Packet Storm
315135 - - - It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface… - CVE-2024-6873 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
315136 - - - A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a … - CVE-2024-6242 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
315137 - - - In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /ins… CWE-304
 Missing Critical Step in Authentication
CVE-2024-6040 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
315138 - - - Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based E… - CVE-2024-41961 2024-08-2 01:45 2024-08-2 Show GitHub Exploit DB Packet Storm
315139 - - - A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of t… CWE-378
 Creation of Temporary File With Insecure Permissions
CVE-2024-7358 2024-08-2 01:45 2024-08-1 Show GitHub Exploit DB Packet Storm
315140 - - - mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack. - CVE-2024-41262 2024-08-2 01:35 2024-08-1 Show GitHub Exploit DB Packet Storm