Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3451 5.2 警告
Physics
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおけるPRNG におけるシードの不正な使用に関する脆弱性 CWE-335
PRNGにおけるシードの不正な使用
CVE-2026-3503 2026-05-1 10:47 2026-03-19 Show GitHub Exploit DB Packet Storm
3452 9.8 緊急
Network
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおける複数の脆弱性 CWE-122
CWE-787
CWE-787
CVE-2026-3548 2026-05-1 10:47 2026-03-19 Show GitHub Exploit DB Packet Storm
3453 5.9 警告
Network
VMware Spring AI VMwareのSpring AIにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-40966 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3454 8.6 重要
Network
VMware Spring AI VMwareのSpring AIにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-40967 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3455 7.5 重要
Adjacent
VMware Spring Boot VMwareのSpring Bootにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-40972 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3456 7 重要
Local
VMware Spring Boot VMwareのSpring Bootにおける安全でない一時ファイルに関する脆弱性 CWE-377
安全でない一時ファイル
CVE-2026-40973 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3457 7.5 重要
Network
VMware Spring Boot VMwareのSpring Bootにおける不十分なランダム値の使用に関する脆弱性 CWE-330
不十分なランダム値の使用
CVE-2026-40975 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3458 9.1 緊急
Network
VMware Spring Boot VMwareのSpring Bootにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40976 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3459 6.7 警告
Local
VMware Spring Boot VMwareのSpring Bootにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-40977 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
3460 8.8 重要
Network
VMware Spring AI VMwareのSpring AIにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-40978 2026-05-1 10:47 2026-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317431 - - - A vulnerability was found in ?????????? Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/con… CWE-22
Path Traversal
CVE-2024-8707 2024-09-12 10:15 2024-09-12 Show GitHub Exploit DB Packet Storm
317432 7.3 HIGH
Local
microsoft office
publisher
Microsoft Publisher Security Feature Bypass Vulnerability NVD-CWE-noinfo
CVE-2024-38226 2024-09-12 10:00 2024-09-11 Show GitHub Exploit DB Packet Storm
317433 - - - A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.Templat… CWE-22
Path Traversal
CVE-2024-8706 2024-09-12 09:15 2024-09-12 Show GitHub Exploit DB Packet Storm
317434 - - - Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. - CVE-2024-28981 2024-09-12 09:15 2024-09-12 Show GitHub Exploit DB Packet Storm
317435 6.1 MEDIUM
Network
friendica friendica Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature. CWE-79
Cross-site Scripting
CVE-2024-27729 2024-09-12 05:29 2024-08-16 Show GitHub Exploit DB Packet Storm
317436 6.5 MEDIUM
Network
elastic apm_server APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-37286 2024-09-12 05:20 2024-08-4 Show GitHub Exploit DB Packet Storm
317437 9.8 CRITICAL
Network
angeljudesuarez airline_reservation_system A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The ma… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7500 2024-09-12 05:07 2024-08-6 Show GitHub Exploit DB Packet Storm
317438 8.8 HIGH
Network
angeljudesuarez tailoring_management_system A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The man… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7506 2024-09-12 05:02 2024-08-6 Show GitHub Exploit DB Packet Storm
317439 9.8 CRITICAL
Network
rainniar bike_delivery_system A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argum… CWE-89
SQL Injection
CVE-2024-7505 2024-09-12 04:53 2024-08-6 Show GitHub Exploit DB Packet Storm
317440 6.5 MEDIUM
Network
cybozu office Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access b… NVD-CWE-noinfo
CVE-2024-39817 2024-09-12 04:36 2024-08-6 Show GitHub Exploit DB Packet Storm