Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3311 9.1 緊急
Network
レッドハット
GNU Project
GnuTLS
Red Hat Enterprise Linux
Red Hat OpenShift Container Platform
GNU Project等の複数ベンダの製品における整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2026-33845 2026-05-7 11:27 2026-04-30 Show GitHub Exploit DB Packet Storm
3312 5.3 警告
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-33857 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
3313 5.3 警告
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける複数の脆弱性 CWE-125
CWE-170
CVE-2026-34032 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
3314 7.5 重要
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-34059 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
3315 6.5 警告
Network
SAP human capital management SAPのhuman capital managementにおけるリクエストに対するレスポンス内容の違いに起因する情報漏えいに関する脆弱性 CWE-204
リクエストに対するレスポンス内容の違いに起因する情報漏えい
CVE-2026-34264 2026-05-7 11:27 2026-04-14 Show GitHub Exploit DB Packet Storm
3316 7.5 重要
Network
Go JOSE project Go JOSE Go JOSE projectのGo JOSEにおけるキャッチされない例外に関する脆弱性 CWE-248
キャッチされない例外
CVE-2026-34986 2026-05-7 11:27 2026-04-6 Show GitHub Exploit DB Packet Storm
3317 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける関数の戻り値に対する不適切なチェックに関する脆弱性 CWE-253
関数の戻り値に対する不適切なチェック
CVE-2026-35339 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3318 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける関数の戻り値に対する不適切なチェックに関する脆弱性 CWE-253
関数の戻り値に対する不適切なチェック
CVE-2026-35340 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3319 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける安全でない一時ファイルに関する脆弱性 CWE-377
安全でない一時ファイル
CVE-2026-35342 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3320 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける常に不適切な制御フローの実装に関する脆弱性 CWE-670
常に不適切な制御フローの実装
CVE-2026-35343 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317541 7.5 HIGH
Network
hms-networks ewon_cosy\+_firmware Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in vers… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2024-33892 2024-09-4 04:18 2024-08-3 Show GitHub Exploit DB Packet Storm
317542 7.2 HIGH
Network
hms-networks ewon_cosy\+_firmware Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s… CWE-78
OS Command 
CVE-2024-33896 2024-09-4 04:02 2024-08-3 Show GitHub Exploit DB Packet Storm
317543 6.6 MEDIUM
Physics
hms-networks ewon_cosy\+_firmware Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is n… CWE-798
 Use of Hard-coded Credentials
CVE-2024-33895 2024-09-4 04:02 2024-08-3 Show GitHub Exploit DB Packet Storm
317544 9.8 CRITICAL
Network
arajajyothibabu school_management_system School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php. CWE-89
SQL Injection
CVE-2024-42568 2024-09-4 03:35 2024-08-20 Show GitHub Exploit DB Packet Storm
317545 7.5 HIGH
Network
tenda fh1206_firmware Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the modino parameter in the fromPptpUserAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) v… CWE-787
 Out-of-bounds Write
CVE-2024-42987 2024-09-4 03:35 2024-08-16 Show GitHub Exploit DB Packet Storm
317546 9.8 CRITICAL
Network
tenda fh1206_firmware An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request. NVD-CWE-noinfo
CVE-2024-42978 2024-09-4 03:35 2024-08-16 Show GitHub Exploit DB Packet Storm
317547 7.5 HIGH
Network
tenda fh1201_firmware Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (… CWE-787
 Out-of-bounds Write
CVE-2024-42948 2024-09-4 03:35 2024-08-16 Show GitHub Exploit DB Packet Storm
317548 9.6 CRITICAL
Network
vtiger vtiger_crm A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via in… CWE-79
Cross-site Scripting
CVE-2024-44778 2024-09-4 03:34 2024-08-30 Show GitHub Exploit DB Packet Storm
317549 9.6 CRITICAL
Network
vtiger vtiger_crm A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via … CWE-79
Cross-site Scripting
CVE-2024-44779 2024-09-4 03:33 2024-08-30 Show GitHub Exploit DB Packet Storm
317550 9.6 CRITICAL
Network
vtiger vtiger_crm A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injec… CWE-79
Cross-site Scripting
CVE-2024-44777 2024-09-4 03:33 2024-08-30 Show GitHub Exploit DB Packet Storm