Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
421 8.1 重要
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-43911 2026-05-20 13:28 2026-05-11 Show GitHub Exploit DB Packet Storm
422 7.5 重要
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-44216 2026-05-20 13:28 2026-05-14 Show GitHub Exploit DB Packet Storm
423 5.3 警告
Network
pyLoad pyLoad pyLoadにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2026-44226 2026-05-20 13:28 2026-05-11 Show GitHub Exploit DB Packet Storm
424 7.5 重要
Network
Netty Netty Nettyにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-44248 2026-05-20 13:28 2026-05-13 Show GitHub Exploit DB Packet Storm
425 6.5 警告
Network
Shellhub Shellhub Shellhubにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-44424 2026-05-20 13:28 2026-05-13 Show GitHub Exploit DB Packet Storm
426 5.4 警告
Network
Shellhub Shellhub Shellhubにおける複数の脆弱性 CWE-1333
CWE-20
CWE-943
CVE-2026-44425 2026-05-20 13:28 2026-05-13 Show GitHub Exploit DB Packet Storm
427 5 警告
Network
openwebui open webui openwebuiのopen webuiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-44550 2026-05-20 13:28 2026-05-15 Show GitHub Exploit DB Packet Storm
428 9.1 緊急
Network
openwebui open webui openwebuiのopen webuiにおける認証に関する脆弱性 CWE-287
CWE-noinfo
CVE-2026-44551 2026-05-20 13:28 2026-05-15 Show GitHub Exploit DB Packet Storm
429 8.7 重要
Network
openwebui open webui openwebuiのopen webuiにおける誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2026-44552 2026-05-20 13:28 2026-05-15 Show GitHub Exploit DB Packet Storm
430 8.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-44553 2026-05-20 13:28 2026-05-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311601 7.8 HIGH
Local
microsoft windows_server_2012
windows_server_2016
windows_server_2022
windows_server_2019
Windows Kernel Elevation of Privilege Vulnerability NVD-CWE-noinfo
CVE-2024-37979 2024-10-17 02:41 2024-10-9 Show GitHub Exploit DB Packet Storm
311602 5.5 MEDIUM
Local
openatom openharmony in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2024-43696 2024-10-17 02:38 2024-10-8 Show GitHub Exploit DB Packet Storm
311603 - - - In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities. - CVE-2024-48714 2024-10-17 02:35 2024-10-16 Show GitHub Exploit DB Packet Storm
311604 - - - In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities. - CVE-2024-48713 2024-10-17 02:35 2024-10-16 Show GitHub Exploit DB Packet Storm
311605 - - - In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities. - CVE-2024-48712 2024-10-17 02:35 2024-10-16 Show GitHub Exploit DB Packet Storm
311606 - - - In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities. - CVE-2024-48710 2024-10-17 02:35 2024-10-16 Show GitHub Exploit DB Packet Storm
311607 9.8 CRITICAL
Network
xerox freeflow_core Pre-Auth RCE via Path Traversal CWE-22
Path Traversal
CVE-2024-47556 2024-10-17 02:34 2024-10-8 Show GitHub Exploit DB Packet Storm
311608 6.1 MEDIUM
Local
qualcomm wsa8835_firmware
wsa8830_firmware
wcd9380_firmware
snapdragon_8\+_gen_2_mobile_platform_firmware
snapdragon_8\+_gen_1_mobile_platform_firmware
snapdragon_8_gen_3_mobile_platform_firmwa…
Information disclosure while sending implicit broadcast containing APP launch information. CWE-863
 Incorrect Authorization
CVE-2024-38425 2024-10-17 02:34 2024-10-7 Show GitHub Exploit DB Packet Storm
311609 9.8 CRITICAL
Network
xerox freeflow_core Pre-Auth RCE via Path Traversal CWE-22
Path Traversal
CVE-2024-47557 2024-10-17 02:33 2024-10-8 Show GitHub Exploit DB Packet Storm
311610 6.8 MEDIUM
Adjacent
netgear ex3700_firmware
ex6100_firmware
ex6120_firmware
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter. CWE-77
Command Injection
CVE-2024-35519 2024-10-17 02:17 2024-10-15 Show GitHub Exploit DB Packet Storm