Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
351 - - 日立 Hitachi Virtual Storage Platform 日立ディスクアレイシステムにおけるSVP 脆弱性対策について (2026年3月分) - CVE-2026-23667
CVE-2026-23668
CVE-2026-23669
CVE-2026-23671
CVE-2026-23672
CVE-2026-23673
CVE-2026-23674
CVE-2026-24282
CVE-2026-24285
CVE-2026-24287
CVE-2026-24288
C…
2026-05-25 11:30 2026-05-20 Show GitHub Exploit DB Packet Storm
352 5.5 警告
Local
Amazon.com, Inc. AWS API MCP Server Amazon.com, Inc.のAWS API MCP Serverにおける代替パスの保護に関する脆弱性 CWE-424
代替パスの不適切な保護
CVE-2026-4270 2026-05-25 10:26 2026-03-16 Show GitHub Exploit DB Packet Storm
353 6.5 警告
Network
ベリタス Veritas InfoScale Operations Manager ベリタスのVeritas InfoScale Operations ManagerにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-44923 2026-05-25 10:26 2026-05-20 Show GitHub Exploit DB Packet Storm
354 5.4 警告
Network
ベリタス Veritas InfoScale Operations Manager ベリタスのVeritas InfoScale Operations Managerにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44924 2026-05-25 10:26 2026-05-20 Show GitHub Exploit DB Packet Storm
355 8.8 重要
Adjacent
ベリタス Veritas InfoScale Operations Manager ベリタスのVeritas InfoScale Operations Managerにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-44925 2026-05-25 10:26 2026-05-20 Show GitHub Exploit DB Packet Storm
356 6.1 警告
Network
SimpleSAMLphp simplesamlphp-casserver SimpleSAMLphpのsimplesamlphp-casserverにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2025-65954 2026-05-25 10:26 2026-05-18 Show GitHub Exploit DB Packet Storm
357 5.3 警告
Network
LupinLin1 JiMeng Web MCP Server LupinLin1のJiMeng Web MCP Serverにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2025-70040 2026-05-25 10:25 2026-03-9 Show GitHub Exploit DB Packet Storm
358 5.4 警告
Network
ERLANG Erlang/ssh
Erlang/OTP
ERLANGのErlang/OTP等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-23942 2026-05-25 10:25 2026-03-13 Show GitHub Exploit DB Packet Storm
359 5.3 警告
Network
ERLANG Erlang/ssh
Erlang/OTP
ERLANGのErlang/OTP等の複数製品における高圧縮データの処理 (データ増幅)に関する脆弱性 CWE-409
高圧縮データの不適切な処理 (データ増幅)
CVE-2026-23943 2026-05-25 10:25 2026-03-13 Show GitHub Exploit DB Packet Storm
360 7.8 重要
Local
Uderzo Software SpaceSniffer Uderzo SoftwareのSpaceSnifferにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-26738 2026-05-25 10:25 2026-03-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311051 - - - The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not … - CVE-2024-50667 2024-11-13 02:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311052 9.8 CRITICAL
Network
gl-inet mt6000_firmware
a1300_firmware
x300b_firmware
ax1800_firmware
axt1800_firmware
mt2500_firmware
mt3000_firmware
x3000_firmware
xe3000_firmware
xe300_firmware
e750_firmwar…
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3… CWE-22
Path Traversal
CVE-2024-39226 2024-11-13 02:35 2024-08-7 Show GitHub Exploit DB Packet Storm
311053 - - - Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access… - CVE-2024-47779 2024-11-13 02:15 2024-10-16 Show GitHub Exploit DB Packet Storm
311054 - - - An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. - CVE-2024-33660 2024-11-13 01:35 2024-11-13 Show GitHub Exploit DB Packet Storm
311055 - - - Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation cou… - CVE-2024-50601 2024-11-13 01:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311056 - - - The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity… - CVE-2024-46966 2024-11-13 01:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311057 - - - The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity co… - CVE-2024-46964 2024-11-13 01:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311058 - - - The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesk… - CVE-2024-46963 2024-11-13 01:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311059 - - - The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMain… - CVE-2024-46962 2024-11-13 01:35 2024-11-12 Show GitHub Exploit DB Packet Storm
311060 - - - A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header informat… - CVE-2024-43432 2024-11-13 01:35 2024-11-11 Show GitHub Exploit DB Packet Storm