Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3281 7.5 重要
Network
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-31711 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3282 8.3 重要
Network
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-31712 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3283 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-31713 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3284 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-31714 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3285 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-31715 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3286 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-31716 2026-05-8 12:05 2026-05-1 Show GitHub Exploit DB Packet Storm
3287 - - (複数のベンダ) (複数の製品) CISA ICS Advisory / ICS Medical Advisory(2026年04月30日) - - 2026-05-7 14:50 2026-05-1 Show GitHub Exploit DB Packet Storm
3288 6.1 警告
Network
opennebula opennebula opennebulaにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-56534 2026-05-7 12:30 2026-04-29 Show GitHub Exploit DB Packet Storm
3289 6.1 警告
Network
opennebula opennebula opennebulaにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-56535 2026-05-7 12:30 2026-04-29 Show GitHub Exploit DB Packet Storm
3290 6.1 警告
Network
opennebula opennebula opennebulaにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-56536 2026-05-7 12:30 2026-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313081 - - - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2024-48910 2024-11-1 21:57 2024-11-1 Show GitHub Exploit DB Packet Storm
313082 - - - DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function. - CVE-2024-51259 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313083 - - - DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function. - CVE-2024-51254 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313084 - - - langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component. - CVE-2024-42835 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313085 - - - A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be e… CWE-78
OS Command 
CVE-2024-8934 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313086 - - - Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attack… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2024-10454 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313087 - - - Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13. CWE-352
 Origin Validation Error
CVE-2024-43984 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313088 - - - Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3. - CVE-2024-43930 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313089 - - - HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. - CVE-2024-30149 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm
313090 6.4 MEDIUM
Network
- - The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and including, 1.0.0 due to insufficient input… CWE-79
Cross-site Scripting
CVE-2024-9446 2024-11-1 21:57 2024-10-31 Show GitHub Exploit DB Packet Storm