|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 16, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 861 | 7.8 |
重要
Local |
Open Source Geospatial Foundation | GDAL | Open Source Geospatial FoundationのGDALにおける複数の脆弱性 |
CWE-119 CWE-122 |
CVE-2026-8086 | 2026-05-11 11:04 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 862 | 7.8 |
重要
Local |
Open Source Geospatial Foundation | GDAL | Open Source Geospatial FoundationのGDALにおける複数の脆弱性 |
CWE-119 CWE-122 |
CVE-2026-8087 | 2026-05-11 11:04 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 863 | 5.5 |
警告
Local |
Open Source Geospatial Foundation | GDAL | Open Source Geospatial FoundationのGDALにおける複数の脆弱性 |
CWE-119 CWE-125 |
CVE-2026-8088 | 2026-05-11 11:03 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 864 | 7.3 |
重要
Network |
Mozilla Foundation |
Mozilla Firefox Mozilla Thunderbird |
Mozilla FoundationのMozilla Firefox等の複数製品における解放済みメモリの使用に関する脆弱性 |
CWE-416
解放済みメモリの使用 |
CVE-2026-8090 | 2026-05-11 11:03 | 2026-05-7 | Show | GitHub Exploit DB Packet Storm |
| 865 | 7.8 |
重要
Local |
Forcepoint LLC. | Next Generation Firewall (NGFW) | Forcepoint LLC.のNext Generation Firewall (NGFW)における不要な特権による実行に関する脆弱性 |
CWE-250 CWE-noinfo |
CVE-2025-12690 | 2026-05-11 11:03 | 2026-03-11 | Show | GitHub Exploit DB Packet Storm |
| 866 | 6.8 |
警告
Network |
vaadin | Vaadin | Vaadin Ltd.のVaadinにおけるパストラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2026-2741 | 2026-05-11 11:03 | 2026-03-10 | Show | GitHub Exploit DB Packet Storm |
| 867 | 5.3 |
警告
Network |
vaadin | Vaadin | Vaadin Ltd.のVaadinにおけるアクセス制御に関する脆弱性 |
CWE-284 CWE-Other |
CVE-2026-2742 | 2026-05-11 11:03 | 2026-03-10 | Show | GitHub Exploit DB Packet Storm |
| 868 | 7.8 |
重要
Local |
ASSA ABLOY | Visionline | ASSA ABLOYのVisionlineにおける複数の脆弱性 |
CWE-250 CWE-276 CWE-732 CWE-732 |
CVE-2026-3315 | 2026-05-11 11:03 | 2026-03-10 | Show | GitHub Exploit DB Packet Storm |
| 869 | 9.8 |
緊急
Network |
NetBox Labs | Netbox-docker | NetBox LabsのNetbox-dockerにおける複数の脆弱性 |
CWE-1392 CWE-798 |
CVE-2023-27573 | 2026-05-11 11:03 | 2026-03-11 | Show | GitHub Exploit DB Packet Storm |
| 870 | 6.1 |
警告
Network |
HCL Technologies Limited | DFX Analytics | HCL Technologies LimitedのDFX Analyticsにおける複数の脆弱性 |
CWE-358 CWE-79 |
CVE-2025-31970 | 2026-05-11 11:03 | 2026-05-6 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 17, 2026, 4:15 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 312271 | 6.5 |
MEDIUM
Network |
gowildchild | visual_sound | The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
CWE-352
Origin Validation Error |
CVE-2024-8047 | 2024-09-28 06:25 | 2024-09-17 | Show | GitHub Exploit DB Packet Storm |
| 312272 | 6.1 |
MEDIUM
Network |
outtolunchproductions | simple_headline_rotator | The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin … |
CWE-79
Cross-site Scripting |
CVE-2024-7860 | 2024-09-28 05:56 | 2024-09-12 | Show | GitHub Exploit DB Packet Storm |
| 312273 | 6.1 |
MEDIUM
Network |
michalaugustyniak | misiek_paypal | The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin a… |
CWE-79
Cross-site Scripting |
CVE-2024-7861 | 2024-09-28 05:52 | 2024-09-12 | Show | GitHub Exploit DB Packet Storm |
| 312274 | 5.7 |
MEDIUM
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks. |
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer |
CVE-2024-7698 | 2024-09-28 04:39 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |
| 312275 | 8.8 |
HIGH
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices. |
CWE-78
OS Command |
CVE-2024-43387 | 2024-09-28 04:33 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |
| 312276 | 8.8 |
HIGH
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices. |
CWE-78
OS Command |
CVE-2024-43386 | 2024-09-28 04:33 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |
| 312277 | 8.8 |
HIGH
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices. |
CWE-78
OS Command |
CVE-2024-43385 | 2024-09-28 04:33 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |
| 312278 | 8.8 |
HIGH
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. |
NVD-CWE-noinfo
|
CVE-2024-43388 | 2024-09-28 04:32 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |
| 312279 | 7.1 |
HIGH
Local |
moxa |
mxview_one mxview_one_central_manager |
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensit… |
CWE-312
Cleartext Storage of Sensitive Information |
CVE-2024-6785 | 2024-09-28 03:59 | 2024-09-21 | Show | GitHub Exploit DB Packet Storm |
| 312280 | 8.8 |
HIGH
Network |
phoenixcontact |
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua… |
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data. |
CWE-78
OS Command |
CVE-2024-7699 | 2024-09-28 03:59 | 2024-09-10 | Show | GitHub Exploit DB Packet Storm |