Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3061 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. FH1202 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のFH1202 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-7034 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
3062 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. FH1202 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のFH1202 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-7035 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
3063 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. i9 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のi9 ファームウェアにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-7036 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
3064 7.3 重要
Network
D-Link Systems, Inc. DIR-822 ファームウェア D-Link CorporationのDIR-822 ファームウェアにおける複数の脆弱性 CWE-74
CWE-77
CVE-2026-7067 2026-05-1 10:41 2026-04-27 Show GitHub Exploit DB Packet Storm
3065 8.8 重要
Adjacent
ディーリンクジャパン株式会社 dir-825 ファームウェア D-Link CorporationのDIR-825 ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-7068 2026-05-1 10:41 2026-04-27 Show GitHub Exploit DB Packet Storm
3066 8 重要
Adjacent
ディーリンクジャパン株式会社 dir-825 ファームウェア D-Link CorporationのDIR-825 ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-7069 2026-05-1 10:41 2026-04-27 Show GitHub Exploit DB Packet Storm
3067 6.1 警告
Local
Artifex Software MuPDF Artifex SoftwareのMuPDFにおける複数の脆弱性 CWE-119
CWE-125
CVE-2026-7233 2026-05-1 10:41 2026-04-28 Show GitHub Exploit DB Packet Storm
3068 7.2 重要
Network
D-Link Systems, Inc. di-8100 ファームウェア D-Link Corporationのdi-8100 ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-7247 2026-05-1 10:41 2026-04-28 Show GitHub Exploit DB Packet Storm
3069 9.4 緊急
Network
D-Link Systems, Inc. di-8100 ファームウェア D-Link Corporationのdi-8100 ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-7248 2026-05-1 10:41 2026-04-28 Show GitHub Exploit DB Packet Storm
3070 8.8 重要
Network
D-Link Systems, Inc. DIR-825M ファームウェア D-Link CorporationのDIR-825M ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-7288 2026-05-1 10:41 2026-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
981 7.1 HIGH
Local
netty netty Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content direc… CWE-93
CRLF Injection
CVE-2026-42586 2026-05-19 03:02 2026-05-14 Show GitHub Exploit DB Packet Storm
982 8.8 HIGH
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored… CWE-79
Cross-site Scripting
CVE-2026-7498 2026-05-19 02:51 2026-05-18 Show GitHub Exploit DB Packet Storm
983 6.3 MEDIUM
Network
- - A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.ph… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-8753 2026-05-19 02:51 2026-05-17 Show GitHub Exploit DB Packet Storm
984 6.3 MEDIUM
Network
- - A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulatio… CWE-22
Path Traversal
CVE-2026-8754 2026-05-19 02:51 2026-05-17 Show GitHub Exploit DB Packet Storm
985 7.3 HIGH
Network
- - A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lea… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-8758 2026-05-19 02:51 2026-05-17 Show GitHub Exploit DB Packet Storm
986 - - - Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete opera… CWE-639
CWE-862
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
CVE-2026-44718 2026-05-19 02:50 2026-05-16 Show GitHub Exploit DB Packet Storm
987 - - - Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list, tables.metadata.list, explorations.list, and form… CWE-862
 Missing Authorization
CVE-2026-44719 2026-05-19 02:50 2026-05-16 Show GitHub Exploit DB Packet Storm
988 4.3 MEDIUM
Network
- - A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation res… CWE-119
CWE-416
Incorrect Access of Indexable Resource ('Range Error') 
 Use After Free
CVE-2026-8746 2026-05-19 02:48 2026-05-17 Show GitHub Exploit DB Packet Storm
989 6.8 MEDIUM
Network
- - Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leadi… CWE-295
Improper Certificate Validation 
CVE-2026-41119 2026-05-19 02:45 2026-05-18 Show GitHub Exploit DB Packet Storm
990 8.1 HIGH
Network
- - Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers… CWE-94
Code Injection
CVE-2026-35194 2026-05-19 02:44 2026-05-16 Show GitHub Exploit DB Packet Storm