Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4411 5.3 警告
Network
MCPHub MCPHub MCPHubにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-13822 2026-05-7 12:07 2026-04-14 Show GitHub Exploit DB Packet Storm
4412 5.3 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2025-14688 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4413 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-36122 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4414 5.3 警告
Network
HCL Technologies Limited HCL AION HCL Technologies LimitedのHCL AIONにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52641 2026-05-7 12:07 2026-04-15 Show GitHub Exploit DB Packet Storm
4415 6.4 警告
Local
レッドハット Ansible Automation Platform レッドハットのAnsible Automation Platformにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57847 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
4416 6.7 警告
Local
レッドハット Red Hat Advanced Cluster Management for Kubernetes レッドハットのRed Hat Advanced Cluster Management for Kubernetesにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57851 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
4417 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2026-1577 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4418 5.5 警告
Local
サムスン android サムスンのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21023 2026-05-7 12:06 2026-04-29 Show GitHub Exploit DB Packet Storm
4419 4.8 警告
Network
VMware Spring Security VMwareのSpring SecurityにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-22751 2026-05-7 12:06 2026-04-21 Show GitHub Exploit DB Packet Storm
4420 8.1 重要
Network
フォーティネット FortiAnalyzer Cloud
FortiManager Cloud
フォーティネットのFortiAnalyzer Cloud等の複数製品におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-22828 2026-05-7 12:06 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314121 8.8 HIGH
Network
microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. NVD-CWE-noinfo
CVE-2024-38139 2024-11-9 00:14 2024-10-16 Show GitHub Exploit DB Packet Storm
314122 7.5 HIGH
Network
ibm websphere_application_server IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulner… CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2024-45085 2024-11-9 00:13 2024-10-16 Show GitHub Exploit DB Packet Storm
314123 9.8 CRITICAL
Network
bg-tek coslat Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069. … CWE-94
Code Injection
CVE-2024-10035 2024-11-9 00:11 2024-11-4 Show GitHub Exploit DB Packet Storm
314124 5.4 MEDIUM
Network
salesagility suitecrm SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site… CWE-79
Cross-site Scripting
CVE-2024-50335 2024-11-9 00:09 2024-11-6 Show GitHub Exploit DB Packet Storm
314125 9.1 CRITICAL
Network
qualcomm wsa8845h_firmware
wsa8845_firmware
wsa8840_firmware
wsa8835_firmware
wsa8832_firmware
wsa8830_firmware
wsa8815_firmware
wsa8810_firmware
wcn7881_firmware
wcn7880_firmware
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. NVD-CWE-noinfo
CVE-2024-38408 2024-11-9 00:07 2024-11-4 Show GitHub Exploit DB Packet Storm
314126 6.1 MEDIUM
Network
flycart discount_rules_for_woocommerce The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… CWE-79
Cross-site Scripting
CVE-2024-8541 2024-11-9 00:07 2024-10-16 Show GitHub Exploit DB Packet Storm
314127 8.8 HIGH
Network
ibm watson_studio_local IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. CWE-352
 Origin Validation Error
CVE-2024-49340 2024-11-9 00:06 2024-10-16 Show GitHub Exploit DB Packet Storm
314128 4.6 MEDIUM
Network
mattermost mattermost_server Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path travers… CWE-352
 Origin Validation Error
CVE-2024-46872 2024-11-9 00:00 2024-10-29 Show GitHub Exploit DB Packet Storm
314129 4.7 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, there… CWE-362
Race Condition
CVE-2024-50135 2024-11-8 23:34 2024-11-6 Show GitHub Exploit DB Packet Storm
314130 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt at eswitch enablin… NVD-CWE-noinfo
CVE-2024-50136 2024-11-8 23:31 2024-11-6 Show GitHub Exploit DB Packet Storm