Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3741 10 緊急
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-183
CWE-441
CWE-918
CVE-2026-42043 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3742 9.1 緊急
Network
axios project axios axios projectのaxiosにおける複数の脆弱性 CWE-1321
CWE-915
CVE-2026-42044 2026-04-30 12:25 2026-04-24 Show GitHub Exploit DB Packet Storm
3743 8.8 重要
Network
HashiCorp Vault HashiCorpのVaultにおける送信データへの重要な情報の挿入に関する脆弱性 CWE-201
送信データへの重要な情報の挿入
CVE-2026-4525 2026-04-30 12:25 2026-04-17 Show GitHub Exploit DB Packet Storm
3744 4.9 警告
Network
IBM IBM Guardium Data Protection IBMのIBM Guardium Data Protectionにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-4917 2026-04-30 12:25 2026-04-23 Show GitHub Exploit DB Packet Storm
3745 4.8 警告
Network
IBM IBM Guardium Data Protection IBMのIBM Guardium Data Protectionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4918 2026-04-30 12:25 2026-04-23 Show GitHub Exploit DB Packet Storm
3746 4.8 警告
Network
IBM IBM Guardium Data Protection IBMのIBM Guardium Data Protectionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4919 2026-04-30 12:25 2026-04-23 Show GitHub Exploit DB Packet Storm
3747 8.6 重要
Network
HashiCorp Vault HashiCorpのVaultにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-5052 2026-04-30 12:25 2026-04-17 Show GitHub Exploit DB Packet Storm
3748 6.5 警告
Network
Rapid7 velociraptor Rapid7のvelociraptorにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-5329 2026-04-30 12:25 2026-04-9 Show GitHub Exploit DB Packet Storm
3749 7.5 重要
Network
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-5477 2026-04-30 12:24 2026-04-10 Show GitHub Exploit DB Packet Storm
3750 5.9 警告
Network
wolfSSL Inc. wolfSSL wolfSSL Inc.のwolfSSLにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-5500 2026-04-30 12:24 2026-04-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314511 8.8 HIGH
Network
acymailing acymailing The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7384 2024-09-27 22:15 2024-08-22 Show GitHub Exploit DB Packet Storm
314512 8.8 HIGH
Network
wpmarketingrobot woocommerce_google_feed_manager The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and… CWE-862
 Missing Authorization
CVE-2024-7258 2024-09-27 22:05 2024-08-23 Show GitHub Exploit DB Packet Storm
314513 4.3 MEDIUM
Network
webba-booking webba_booking The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() func… CWE-862
 Missing Authorization
CVE-2024-8432 2024-09-27 21:58 2024-09-24 Show GitHub Exploit DB Packet Storm
314514 6.1 MEDIUM
Network
fatcatapps pixel_cat The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions u… CWE-79
Cross-site Scripting
CVE-2024-8544 2024-09-27 21:57 2024-09-24 Show GitHub Exploit DB Packet Storm
314515 5.4 MEDIUM
Network
ggnome garden_gnome_package The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanit… CWE-79
Cross-site Scripting
CVE-2024-8657 2024-09-27 21:56 2024-09-24 Show GitHub Exploit DB Packet Storm
314516 6.1 MEDIUM
Network
ibericode koko_analytics The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1… CWE-79
Cross-site Scripting
CVE-2024-8662 2024-09-27 21:54 2024-09-24 Show GitHub Exploit DB Packet Storm
314517 7.2 HIGH
Network
presstigers simple_job_board The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This… CWE-502
 Deserialization of Untrusted Data
CVE-2024-7351 2024-09-27 21:48 2024-08-24 Show GitHub Exploit DB Packet Storm
314518 7.2 HIGH
Network
benjaminrojas wp_editor The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authen… CWE-502
 Deserialization of Untrusted Data
CVE-2022-2446 2024-09-27 10:09 2024-09-14 Show GitHub Exploit DB Packet Storm
314519 5.4 MEDIUM
Network
arnoldgoodway neighborly The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficie… CWE-79
Cross-site Scripting
CVE-2024-5869 2024-09-27 10:06 2024-09-14 Show GitHub Exploit DB Packet Storm
314520 5.4 MEDIUM
Network
samiahmedsiddiqui custom_permalinks The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on tag names… CWE-79
Cross-site Scripting
CVE-2023-0926 2024-09-27 10:01 2024-08-24 Show GitHub Exploit DB Packet Storm