|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 18, 2026, 12:09 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 2931 | 8.1 |
重要
Network |
OpenBSD | OpenSSH | OpenBSDのOpenSSHにおけるパーミッションの不適切な保持に関する脆弱性 |
CWE-281
パーミッションの不適切な保持 |
CVE-2026-35385 | 2026-04-28 10:12 | 2026-04-2 | Show | GitHub Exploit DB Packet Storm |
| 2932 | 8.1 |
重要
Network |
OpenBSD | OpenSSH | OpenBSDのOpenSSHにおける不適切な動作順序に関する脆弱性 |
CWE-696
不適切な動作順序 |
CVE-2026-35386 | 2026-04-28 10:12 | 2026-04-2 | Show | GitHub Exploit DB Packet Storm |
| 2933 | 6.5 |
警告
Network |
OpenBSD | OpenSSH | OpenBSDのOpenSSHにおける常に不適切な制御フローの実装に関する脆弱性 |
CWE-670
常に不適切な制御フローの実装 |
CVE-2026-35387 | 2026-04-28 10:12 | 2026-04-2 | Show | GitHub Exploit DB Packet Storm |
| 2934 | 2.5 |
低
Local |
OpenBSD | OpenSSH | OpenBSDのOpenSSHにおける保護されていない代替チャネルに関する脆弱性 |
CWE-420
保護されていない代替チャネル |
CVE-2026-35388 | 2026-04-28 10:12 | 2026-04-2 | Show | GitHub Exploit DB Packet Storm |
| 2935 | 8.8 |
重要
Network |
neutrinolabs | xrdp | neutrinolabsのxrdpにおけるヒープベースのバッファオーバーフローの脆弱性 |
CWE-122
ヒープオーバーフロー |
CVE-2026-35512 | 2026-04-28 10:12 | 2026-04-17 | Show | GitHub Exploit DB Packet Storm |
| 2936 | 4.3 |
警告
Network |
Apache Software Foundation | Apache Airflow | Apache Software FoundationのApache Airflowにおけるアクセス制御の不十分な粒度に関する脆弱性 |
CWE-1220
アクセス制御の不十分な粒度 |
CVE-2026-38743 | 2026-04-28 10:12 | 2026-04-24 | Show | GitHub Exploit DB Packet Storm |
| 2937 | 7.7 |
重要
Network |
Lee Peuker | Movary | Lee PeukerのMovaryにおけるサーバサイドのリクエストフォージェリの脆弱性 |
CWE-918
サーバサイドリクエストフォージェリ |
CVE-2026-40348 | 2026-04-28 10:12 | 2026-04-18 | Show | GitHub Exploit DB Packet Storm |
| 2938 | 8.8 |
重要
Network |
Lee Peuker | Movary | Lee PeukerのMovaryにおける認証の欠如に関する脆弱性 |
CWE-862
認証の欠如 |
CVE-2026-40349 | 2026-04-28 10:12 | 2026-04-18 | Show | GitHub Exploit DB Packet Storm |
| 2939 | 8.8 |
重要
Network |
Lee Peuker | Movary | Lee PeukerのMovaryにおける不正な認証に関する脆弱性 |
CWE-863
不正な認証 |
CVE-2026-40350 | 2026-04-28 10:12 | 2026-04-18 | Show | GitHub Exploit DB Packet Storm |
| 2940 | 8.8 |
重要
Network |
Apache Software Foundation |
ActiveMQ Broker Apache ActiveMQ |
Apache Software FoundationのApache ActiveMQ等の複数製品における複数の脆弱性 |
CWE-20 CWE-94 |
CVE-2026-40466 | 2026-04-28 10:12 | 2026-04-24 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 18, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 314431 | 8.8 |
HIGH
Network |
easy_test_online_learning_and_testing_platform_project | easy_test_online_learning_and_testing_platform | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbit… |
CWE-89
SQL Injection |
CVE-2024-8327 | 2024-09-5 02:11 | 2024-08-30 | Show | GitHub Exploit DB Packet Storm |
| 314432 | 5.5 |
MEDIUM
Local |
openatom | openharmony | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
CWE-125
Out-of-bounds Read |
CVE-2024-38382 | 2024-09-5 02:10 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314433 | 7.8 |
HIGH
Local |
qualcomm |
apq8017_firmware aqt1000_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8108_firmwa… |
Memory corruption when Alternative Frequency offset value is set to 255. |
CWE-787
Out-of-bounds Write |
CVE-2024-33042 | 2024-09-5 02:08 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314434 | 7.8 |
HIGH
Local |
qualcomm |
fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm5430_firmware qcm6490_firmware qcs5430_firmware qcs6490_firmware video_collaboration_vc3_firmware… |
Memory corruption when the captureRead QDCM command is invoked from user-space. |
CWE-125
Out-of-bounds Read |
CVE-2024-33047 | 2024-09-5 02:07 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314435 | 7.5 |
HIGH
Network |
qualcomm |
ar8035_firmware ar9380_firmware csr8811_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_… |
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
CWE-125
Out-of-bounds Read |
CVE-2024-33050 | 2024-09-5 02:07 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314436 | 7.8 |
HIGH
Local |
qualcomm |
fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm5430_firmware qcm6490_firmware qcm8550_firmware qcs5430_firmware qcs6490_firmware qcs8550_firm… |
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. |
CWE-787
Out-of-bounds Write |
CVE-2024-33054 | 2024-09-5 02:06 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314437 | 7.8 |
HIGH
Local |
qualcomm |
315_5g_iot_firmware aqt1000_firmware ar8031_firmware ar8035_firmware c-v2x_9150_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmwar… |
Memory corruption when two threads try to map and unmap a single node simultaneously. |
CWE-416
Use After Free |
CVE-2024-33060 | 2024-09-5 02:06 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314438 | 7.5 |
HIGH
Network |
qualcomm |
ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_firmware immersive_home_214_firmware immersive_home_2… |
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
CWE-125
Out-of-bounds Read |
CVE-2024-33057 | 2024-09-5 02:06 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314439 | 7.8 |
HIGH
Local |
qualcomm |
ar8035_firmware c-v2x_9150_firmware fastconnect_7800_firmware qca6574a_firmware qca6584au_firmware qca6595au_firmware qca6696_firmware qca6698aq_firmware qca8081_firmware q… |
Memory corruption while processing concurrent IOCTL calls. |
CWE-416
Use After Free |
CVE-2024-38401 | 2024-09-5 02:05 | 2024-09-2 | Show | GitHub Exploit DB Packet Storm |
| 314440 | 4.3 |
MEDIUM
Network |
mattermost | mattermost_server | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a… |
NVD-CWE-noinfo
|
CVE-2024-41162 | 2024-09-5 02:03 | 2024-08-2 | Show | GitHub Exploit DB Packet Storm |