Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3561 9.1 緊急
Network
サムスン escargot サムスンのescargotにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-25206 2026-04-30 12:16 2026-04-13 Show GitHub Exploit DB Packet Storm
3562 9.8 緊急
Network
サムスン escargot サムスンのescargotにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-25207 2026-04-30 12:16 2026-04-13 Show GitHub Exploit DB Packet Storm
3563 9.8 緊急
Network
サムスン escargot サムスンのescargotにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-25208 2026-04-30 12:16 2026-04-13 Show GitHub Exploit DB Packet Storm
3564 9.1 緊急
Network
サムスン escargot サムスンのescargotにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-25209 2026-04-30 12:16 2026-04-13 Show GitHub Exploit DB Packet Storm
3565 7.8 重要
Local
デル Alienware Command Center デルのAlienware Command Centerにおける不要な特権による実行に関する脆弱性 CWE-250
不要な特権による実行
CVE-2026-25908 2026-04-30 12:16 2026-04-27 Show GitHub Exploit DB Packet Storm
3566 7.2 重要
Network
デル PowerProtect DP Series Appliance
data domain operating system
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-26942 2026-04-30 12:16 2026-04-20 Show GitHub Exploit DB Packet Storm
3567 7.2 重要
Network
デル PowerProtect DP Series Appliance
data domain operating system
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-26943 2026-04-30 12:16 2026-04-20 Show GitHub Exploit DB Packet Storm
3568 6.7 警告
Local
デル PowerProtect DP Series Appliance
data domain operating system
デルのdata domain operating system等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-26951 2026-04-30 12:16 2026-04-20 Show GitHub Exploit DB Packet Storm
3569 8.8 重要
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-27172 2026-04-30 12:16 2026-04-27 Show GitHub Exploit DB Packet Storm
3570 7.8 重要
Local
ggml.ai llama.cpp ggml.aiのllama.cppにおける複数の脆弱性 CWE-122
CWE-190
CVE-2026-27940 2026-04-30 12:16 2026-03-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314611 - - - An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. - CVE-2024-32843 2024-09-12 11:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314612 - - - An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. - CVE-2024-32842 2024-09-12 11:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314613 - - - An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. - CVE-2024-32840 2024-09-12 11:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314614 - - - Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. - CVE-2024-29847 2024-09-12 11:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314615 - - - A vulnerability was found in ?????????? Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/con… CWE-22
Path Traversal
CVE-2024-8707 2024-09-12 10:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314616 7.3 HIGH
Local
microsoft office
publisher
Microsoft Publisher Security Feature Bypass Vulnerability NVD-CWE-noinfo
CVE-2024-38226 2024-09-12 10:00 2024-09-11 Show GitHub Exploit DB Packet Storm
314617 - - - A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.Templat… CWE-22
Path Traversal
CVE-2024-8706 2024-09-12 09:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314618 - - - Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. - CVE-2024-28981 2024-09-12 09:15 2024-09-12 Show GitHub Exploit DB Packet Storm
314619 6.1 MEDIUM
Network
friendica friendica Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature. CWE-79
Cross-site Scripting
CVE-2024-27729 2024-09-12 05:29 2024-08-16 Show GitHub Exploit DB Packet Storm
314620 6.5 MEDIUM
Network
elastic apm_server APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-37286 2024-09-12 05:20 2024-08-4 Show GitHub Exploit DB Packet Storm