Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2941 8.8 重要
Network
Snorkel AI, Inc. Snorkel Snorkel AI, Inc.のSnorkelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-31223 2026-05-15 10:54 2026-05-12 Show GitHub Exploit DB Packet Storm
2942 8.8 重要
Network
Snorkel AI, Inc. Snorkel Snorkel AI, Inc.のSnorkelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-31224 2026-05-15 10:54 2026-05-12 Show GitHub Exploit DB Packet Storm
2943 8.8 重要
Network
デル Dell Automation Platform デルのDell Automation Platformにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-32658 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
2944 7.8 重要
Local
WELLBIA.COM CO.,LTD XIGNCODE3 WELLBIA.COM CO.,LTDのXIGNCODE3における不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-3609 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
2945 4.9 警告
Network
aiven Aiven Operator aivenのAiven Operatorにおける複数の脆弱性 CWE-269
CWE-441
CVE-2026-39961 2026-05-15 10:54 2026-04-9 Show GitHub Exploit DB Packet Storm
2946 8.8 重要
Network
AGiXT AGiXT AGiXTにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-39981 2026-05-15 10:54 2026-04-9 Show GitHub Exploit DB Packet Storm
2947 7.5 重要
Network
Succinct SP1 SuccinctのSP1における複数の脆弱性 CWE-345
CWE-354
CVE-2026-40323 2026-05-15 10:54 2026-04-18 Show GitHub Exploit DB Packet Storm
2948 8.8 重要
Network
Electric Sync-service ElectricのSync-serviceにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-40906 2026-05-15 10:54 2026-04-21 Show GitHub Exploit DB Packet Storm
2949 6.5 警告
Network
Apache Software Foundation Apache-airflow-providers-elasticsearch Apache Software FoundationのApache-airflow-providers-elasticsearchにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-41018 2026-05-15 10:54 2026-05-11 Show GitHub Exploit DB Packet Storm
2950 6.5 警告
Network
BETTER-AUTH. Better Auth OAuth Provider BETTER-AUTH.のBetter Auth OAuth Providerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41427 2026-05-15 10:54 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312171 - - - A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint. - CVE-2024-31695 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312172 - - - Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have unintended impacts… - CVE-2024-9834 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312173 - - - There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthor… - CVE-2024-9832 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312174 5.4 MEDIUM
Network
- - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2024-49025 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312175 - - - Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes.… CWE-94
Code Injection
CVE-2024-49362 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312176 - - - A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit… - CVE-2024-6068 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312177 - - - A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to hav… - CVE-2024-37285 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312178 - - - matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead t… CWE-147
 Improper Neutralization of Input Terminators
CVE-2024-52505 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312179 - - - common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the applicatio… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-52302 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm
312180 - - - HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios. - CVE-2024-42188 2024-11-15 22:58 2024-11-15 Show GitHub Exploit DB Packet Storm