Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3231 9.8 緊急
Network
asrmicro asr1803 ファームウェア asrmicroのasr1803 ファームウェアにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-42799 2026-05-7 11:25 2026-04-30 Show GitHub Exploit DB Packet Storm
3232 8.5 重要
Network
OpenStack Openstack Keystone OpenStackのOpenstack Keystoneにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-43001 2026-05-7 11:25 2026-05-1 Show GitHub Exploit DB Packet Storm
3233 9.8 緊急
Network
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-43037 2026-05-7 11:25 2026-05-1 Show GitHub Exploit DB Packet Storm
3234 9.8 緊急
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける根本の脆弱性による認証回避の脆弱性 CWE-305
根本の脆弱性による認証回避
CVE-2026-4670 2026-05-7 11:25 2026-04-30 Show GitHub Exploit DB Packet Storm
3235 8.8 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-5174 2026-05-7 11:25 2026-04-30 Show GitHub Exploit DB Packet Storm
3236 6.5 警告
Network
GNU Project GNU C Library GNU ProjectのGNU C Libraryにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-6238 2026-05-7 11:25 2026-04-28 Show GitHub Exploit DB Packet Storm
3237 8.1 重要
Network
langflow langflow langflowにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-6542 2026-05-7 11:25 2026-04-30 Show GitHub Exploit DB Packet Storm
3238 6.5 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-6706 2026-05-7 11:25 2026-04-28 Show GitHub Exploit DB Packet Storm
3239 6.5 警告
Adjacent
Amazon.com, Inc. freertos-plus-tcp Amazon.com, Inc.のfreertos-plus-tcpにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-7422 2026-05-7 11:25 2026-04-29 Show GitHub Exploit DB Packet Storm
3240 6.5 警告
Adjacent
Amazon.com, Inc. freertos-plus-tcp Amazon.com, Inc.のfreertos-plus-tcpにおける整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2026-7423 2026-05-7 11:25 2026-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
316241 7.8 HIGH
Local
intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. NVD-CWE-noinfo
CVE-2024-26022 2024-09-7 05:16 2024-08-14 Show GitHub Exploit DB Packet Storm
316242 7.8 HIGH
Local
intel oneapi_base_toolkit
advisor
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-276
Incorrect Default Permissions 
CVE-2024-26025 2024-09-7 03:54 2024-08-14 Show GitHub Exploit DB Packet Storm
316243 7.8 HIGH
Local
intel simics_package_manager Uncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2024-26027 2024-09-7 03:52 2024-08-14 Show GitHub Exploit DB Packet Storm
316244 5.5 MEDIUM
Local
intel memory_and_storage_tool_gui Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access. CWE-276
Incorrect Default Permissions 
CVE-2024-27461 2024-09-7 03:45 2024-08-14 Show GitHub Exploit DB Packet Storm
316245 7.8 HIGH
Local
intel graphics_performance_analyzers Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2024-28046 2024-09-7 03:40 2024-08-14 Show GitHub Exploit DB Packet Storm
316246 5.5 MEDIUM
Local
intel arc_a_graphics
iris_xe_graphics
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access. NVD-CWE-noinfo
CVE-2024-28050 2024-09-7 03:38 2024-08-14 Show GitHub Exploit DB Packet Storm
316247 7.3 HIGH
Local
intel oneapi_hpc_toolkit
trace_analyzer_and_collector
Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2024-28172 2024-09-7 03:36 2024-08-14 Show GitHub Exploit DB Packet Storm
316248 7.3 HIGH
Local
intel mpi_library
oneapi_hpc_toolkit
Uncontrolled search path for some Intel(R) MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2024-28876 2024-09-7 03:35 2024-08-14 Show GitHub Exploit DB Packet Storm
316249 9.8 CRITICAL
Network
lopalopa music_management_system Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter. CWE-89
SQL Injection
CVE-2024-42783 2024-09-7 03:31 2024-08-22 Show GitHub Exploit DB Packet Storm
316250 7.2 HIGH
Network
ethyca fides Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering e… CWE-94
Code Injection
CVE-2024-45053 2024-09-7 03:20 2024-09-5 Show GitHub Exploit DB Packet Storm