Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3831 7.8 重要
Local
Foxit pdf editor
pdf reader
Foxitのpdf editor等の複数製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-3779 2026-04-30 11:02 2026-04-1 Show GitHub Exploit DB Packet Storm
3832 7.8 重要
Local
Foxit pdf editor
pdf reader
Foxitのpdf editor等の複数製品における信頼できない検索パスに関する脆弱性 CWE-426
信頼性のない検索パス
CVE-2026-3780 2026-04-30 11:02 2026-04-1 Show GitHub Exploit DB Packet Storm
3833 8.2 重要
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-40022 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3834 7.8 重要
Local
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40048 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3835 5.9 警告
Network
opentelemetry opentelemetry opentelemetryにおける過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-40182 2026-04-30 11:02 2026-04-23 Show GitHub Exploit DB Packet Storm
3836 9.9 緊急
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける大文字と小文字の区別の不適切な処理に関する脆弱性 CWE-178
大文字と小文字の区別の不適切な処理
CVE-2026-40453 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3837 8.8 重要
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40473 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3838 8.8 重要
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40858 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3839 9.8 緊急
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40860 2026-04-30 11:02 2026-04-27 Show GitHub Exploit DB Packet Storm
3840 7.7 重要
Network
argoproj Argo Workflows Argo Project AuthorsのArgo Workflowsにおける配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2026-40886 2026-04-30 11:02 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 - - - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enu… CWE-862
 Missing Authorization
CVE-2026-8237 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
72 - - - Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns int… CWE-862
 Missing Authorization
CVE-2026-8236 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
73 - - - Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnera… CWE-79
Cross-site Scripting
CVE-2026-8139 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
74 - - - In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CM… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7890 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
75 - - - For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and r… CWE-1287
 Improper Validation of Specified Type of Input
CVE-2026-7887 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
76 - - - Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-7886 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
77 - - - Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and procee… CWE-352
 Origin Validation Error
CVE-2026-7882 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
78 - - - Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-7881 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
79 - - - In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypa… CWE-862
 Missing Authorization
CVE-2026-7879 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm
80 9.8 CRITICAL
Network
- - The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versio… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-6960 2026-05-22 07:16 2026-05-22 Show GitHub Exploit DB Packet Storm