Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
911 9.8 緊急
Network
The PHP Group PHP The PHP GroupのPHPにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-7261 2026-05-14 10:15 2026-05-10 Show GitHub Exploit DB Packet Storm
912 7.5 重要
Network
The PHP Group PHP The PHP GroupのPHPにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-7262 2026-05-14 10:15 2026-05-10 Show GitHub Exploit DB Packet Storm
913 7.5 重要
Network
The PHP Group PHP The PHP GroupのPHPにおける複数の脆弱性 CWE-404
CWE-835
CVE-2026-7263 2026-05-14 10:15 2026-05-10 Show GitHub Exploit DB Packet Storm
914 4.4 警告
Local
Ivanti secure access client Ivantiのsecure access clientにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2026-7431 2026-05-14 10:15 2026-05-12 Show GitHub Exploit DB Packet Storm
915 7 重要
Local
Ivanti secure access client Ivantiのsecure access clientにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-7432 2026-05-14 10:14 2026-05-12 Show GitHub Exploit DB Packet Storm
916 8.8 重要
Network
SUN NET TECHNOLOGIES CO., LTD. eHRD CTMS SUN NET TECHNOLOGIES CO., LTD.のeHRD CTMSにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-7489 2026-05-14 10:14 2026-05-2 Show GitHub Exploit DB Packet Storm
917 7.5 重要
Network
The PHP Group PHP The PHP GroupのPHPにおける複数の脆弱性 CWE-125
CWE-190
CVE-2026-7568 2026-05-14 10:14 2026-05-10 Show GitHub Exploit DB Packet Storm
918 6.5 警告
Network
Ivanti Ivanti Endpoint Manager IvantiのIvanti Endpoint Managerにおける危険なメソッドや機能の公開に関する脆弱性 CWE-749
危険なメソッドや機能の公開
CVE-2026-8109 2026-05-14 10:14 2026-05-12 Show GitHub Exploit DB Packet Storm
919 7.8 重要
Local
Ivanti Ivanti Endpoint Manager IvantiのIvanti Endpoint Managerにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2026-8110 2026-05-14 10:14 2026-05-12 Show GitHub Exploit DB Packet Storm
920 8.8 重要
Network
Ivanti Ivanti Endpoint Manager IvantiのIvanti Endpoint ManagerにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-8111 2026-05-14 10:14 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1441 - - - Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a node with a malicious … CWE-943
 Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-42156 2026-05-14 01:10 2026-05-13 Show GitHub Exploit DB Packet Storm
1442 - - - Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malici… CWE-79
Cross-site Scripting
CVE-2026-42157 2026-05-14 01:10 2026-05-13 Show GitHub Exploit DB Packet Storm
1443 10.0 CRITICAL
Network
- - ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard … CWE-94
Code Injection
CVE-2026-42288 2026-05-14 01:10 2026-05-13 Show GitHub Exploit DB Packet Storm
1444 6.5 MEDIUM
Network
open5gs open5gs A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation cause… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8249 2026-05-14 01:10 2026-05-11 Show GitHub Exploit DB Packet Storm
1445 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8228 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm
1446 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8227 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm
1447 7.5 HIGH
Network
open5gs open5gs A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation result… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8223 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm
1448 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8192 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm
1449 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os … CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8191 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm
1450 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwa… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8190 2026-05-14 01:10 2026-05-10 Show GitHub Exploit DB Packet Storm