Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
831 7.5 重要
Network
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
インターネット キー交換 (IKE) プロトコルのサービス拒否の脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-35424 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
832 5.4 警告
Network
Frappe Frappe Frappeにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-3837 2026-05-18 12:15 2026-04-22 Show GitHub Exploit DB Packet Storm
833 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Windows カーネルの特権の昇格の脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-40369 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
834 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Microsoft Cryptographic Services の特権の昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40377 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
835 6.2 警告
Physics
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows ボリューム マネージャー拡張ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-125
CWE-197
CVE-2026-40380 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
836 7.5 重要
Network
PHPOffice PhpSpreadsheet PHPOfficeのPhpSpreadsheetにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-40902 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
837 6.8 警告
Adjacent
VMware Spring Boot VMwareのSpring Bootにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40970 2026-05-18 12:15 2026-04-27 Show GitHub Exploit DB Packet Storm
838 9.1 緊急
Network
VMware Spring Boot VMwareのSpring Bootにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40971 2026-05-18 12:15 2026-04-27 Show GitHub Exploit DB Packet Storm
839 9.8 緊急
Network
VMware Spring Boot VMwareのSpring Bootにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40974 2026-05-18 12:15 2026-04-28 Show GitHub Exploit DB Packet Storm
840 7.2 重要
Network
SonicWALL SMA7200 ファームウェア
SMA7210 ファームウェア
SMA8200v
SMA6200 ファームウェア
SMA6210 ファームウェア
SonicWALLのSMA6200 ファームウェア等の複数製品におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-4112 2026-05-18 12:15 2026-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311511 4.9 MEDIUM
Network
enalean tuleap Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 1… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2024-47766 2024-10-17 22:48 2024-10-15 Show GitHub Exploit DB Packet Storm
311512 6.1 MEDIUM
Network
wp-slimstat slimstat_analytics The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization … CWE-79
Cross-site Scripting
CVE-2024-9548 2024-10-17 22:46 2024-10-15 Show GitHub Exploit DB Packet Storm
311513 5.3 MEDIUM
Network
xplodedthemes wpide The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser libra… NVD-CWE-noinfo
CVE-2024-9546 2024-10-17 22:34 2024-10-15 Show GitHub Exploit DB Packet Storm
311514 6.5 MEDIUM
Adjacent
microsoft windows_server_2022_23h2
windows_10_1809
windows_11_21h2
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_22h2
windows_server_2019
Windows Mobile Broadband Driver Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43559 2024-10-17 22:31 2024-10-9 Show GitHub Exploit DB Packet Storm
311515 6.5 MEDIUM
Adjacent
microsoft windows_server_2022_23h2
windows_10_1809
windows_11_21h2
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_22h2
windows_server_2019
Windows Mobile Broadband Driver Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43558 2024-10-17 22:31 2024-10-9 Show GitHub Exploit DB Packet Storm
311516 6.5 MEDIUM
Adjacent
microsoft windows_server_2022_23h2
windows_10_1809
windows_11_21h2
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_22h2
windows_server_2019
Windows Mobile Broadband Driver Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43557 2024-10-17 22:31 2024-10-9 Show GitHub Exploit DB Packet Storm
311517 4.9 MEDIUM
Network
splunk splunk In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splun… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-45738 2024-10-17 22:17 2024-10-15 Show GitHub Exploit DB Packet Storm
311518 4.9 MEDIUM
Network
splunk splunk In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you con… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-45739 2024-10-17 22:16 2024-10-15 Show GitHub Exploit DB Packet Storm
311519 5.4 MEDIUM
Network
splunk splunk
splunk_cloud_platform
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malic… CWE-79
Cross-site Scripting
CVE-2024-45740 2024-10-17 22:14 2024-10-15 Show GitHub Exploit DB Packet Storm
311520 5.4 MEDIUM
Network
splunk splunk_cloud_platform
splunk
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk role… CWE-79
Cross-site Scripting
CVE-2024-45741 2024-10-17 22:12 2024-10-15 Show GitHub Exploit DB Packet Storm