Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3321 7.4 重要
Network
axios project axios axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-42033 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3322 5.3 警告
Network
axios project axios axios projectのaxiosにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42034 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3323 7.4 重要
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-113
CWE-1321
CVE-2026-42035 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3324 5.3 警告
Network
axios project axios axios projectのaxiosにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42036 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3325 5.3 警告
Network
axios project axios axios projectのaxiosにおけるCRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2026-42037 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3326 7.5 重要
Network
axios project axios axios projectのaxiosにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-42038 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3327 7.5 重要
Network
axios project axios axios projectのaxiosにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-42039 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3328 3.7
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-116
CWE-626
CVE-2026-42040 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3329 6.5 警告
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-1321
CWE-287
CVE-2026-42041 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3330 5.4 警告
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-183
CWE-201
CVE-2026-42042 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314631 - - - Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an auth… - CVE-2024-23906 2024-09-11 13:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314632 - - - In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileg… - CVE-2024-40662 2024-09-11 09:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314633 - - - In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution … - CVE-2024-40658 2024-09-11 09:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314634 - - - In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with n… - CVE-2024-40657 2024-09-11 09:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314635 - - - In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background due to a permissions bypass. This could lead to loc… - CVE-2024-40655 2024-09-11 09:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314636 - - - In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalatio… - CVE-2024-40652 2024-09-11 09:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314637 - - - An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementat… - CVE-2024-45193 2024-09-11 04:35 2024-08-23 Show GitHub Exploit DB Packet Storm
314638 - - - An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: T… - CVE-2024-45192 2024-09-11 04:35 2024-08-23 Show GitHub Exploit DB Packet Storm
314639 - - - An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for t… - CVE-2024-45191 2024-09-11 04:35 2024-08-23 Show GitHub Exploit DB Packet Storm
314640 6.1 MEDIUM
Network
online_food_ordering_system_project online_food_ordering_system A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page.… CWE-79
Cross-site Scripting
CVE-2024-8604 2024-09-11 04:14 2024-09-10 Show GitHub Exploit DB Packet Storm