Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4041 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F451 Firmware Shenzhen Tenda Technology Co.,Ltd.のF451 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6137 2026-05-1 10:41 2026-04-13 Show GitHub Exploit DB Packet Storm
4042 7.5 重要
Network
Cesanta Mongoose CesantaのMongooseにおける複数の脆弱性 CWE-404
CWE-835
CVE-2026-6985 2026-05-1 10:41 2026-04-25 Show GitHub Exploit DB Packet Storm
4043 3.7
Network
Cesanta Mongoose CesantaのMongooseにおける複数の脆弱性 CWE-345
CWE-347
CVE-2026-6986 2026-05-1 10:41 2026-04-25 Show GitHub Exploit DB Packet Storm
4044 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. HG10 Firmware Shenzhen Tenda Technology Co.,Ltd.のHG10 Firmwareにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-6988 2026-05-1 10:41 2026-04-25 Show GitHub Exploit DB Packet Storm
4045 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F453 Firmware Shenzhen Tenda Technology Co.,Ltd.のF453 Firmwareにおける複数の脆弱性 CWE-74
CWE-77
CVE-2026-6989 2026-05-1 10:41 2026-04-25 Show GitHub Exploit DB Packet Storm
4046 7.2 重要
Network
シスコシステムズ (Linksys) mr9600 ファームウェア Linksysのmr9600 ファームウェアにおける複数の脆弱性 CWE-77
CWE-78
CVE-2026-6992 2026-05-1 10:41 2026-04-25 Show GitHub Exploit DB Packet Storm
4047 4.8 警告
Network
D-Link Systems, Inc. DSL-2740R ファームウェア D-Link CorporationのDSL-2740R ファームウェアにおける複数の脆弱性 CWE-79
CWE-94
CVE-2026-7027 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
4048 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. FH1202 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のFH1202 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-7034 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
4049 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. FH1202 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のFH1202 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-7035 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
4050 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. i9 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のi9 ファームウェアにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-7036 2026-05-1 10:41 2026-04-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314261 - - - Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service … CWE-1333
 Inefficient Regular Expression Complexity
CVE-2020-26308 2024-10-28 22:58 2024-10-27 Show GitHub Exploit DB Packet Storm
314262 - - - HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of S… CWE-1333
 Inefficient Regular Expression Complexity
CVE-2020-26307 2024-10-28 22:58 2024-10-27 Show GitHub Exploit DB Packet Storm
314263 - - - Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or more regular expressions that are vulnerabl… CWE-1333
 Inefficient Regular Expression Complexity
CVE-2020-26306 2024-10-28 22:58 2024-10-27 Show GitHub Exploit DB Packet Storm
314264 9.8 CRITICAL
Network
- - The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on th… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2024-9501 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314265 7.5 HIGH
Network
- - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to… CWE-862
 Missing Authorization
CVE-2024-10402 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314266 6.4 MEDIUM
Network
- - The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to insufficient input san… CWE-79
Cross-site Scripting
CVE-2024-10117 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314267 7.3 HIGH
Network
- - The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowin… - CVE-2024-9772 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314268 6.4 MEDIUM
Network
- - The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due to insufficient input sanitization and o… - CVE-2024-9116 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314269 4.3 MEDIUM
Network
- - The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.1 via the getTemplateContent function in src/widgets/cla… CWE-200
Information Exposure
CVE-2024-10357 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm
314270 - - - NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability might lead to inform… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-0128 2024-10-28 22:58 2024-10-26 Show GitHub Exploit DB Packet Storm