Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 10:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1291 5.5 警告
Local
クアルコム X2000094 ファームウェア
XG101002 ファームウェア
WSA8835 ファームウェア
IQX7181 Firmware
WCD9370 ファームウェア
X2000077 ファームウェア
XG101032 ファームウェア
Snapdragon 8CX G…
クアルコムのCologne ファームウェア等の複数製品における複数の脆弱性 CWE-125
CWE-126
CVE-2025-47406 2026-05-8 12:11 2026-05-4 Show GitHub Exploit DB Packet Storm
1292 7 重要
Local
クアルコム SAR2130P Firmware
QXM1086 Firmware
Snapdragon W5+ Gen 1 Wearable Firmware
QXM1096 Firmware
Snapdragon 4 Gen 2 Mobile Firmw…
クアルコムのCQ7790 Firmware等の複数製品におけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2025-47407 2026-05-8 12:11 2026-05-4 Show GitHub Exploit DB Packet Storm
1293 7.8 重要
Local
クアルコム IQX7181 Firmware
SNAPDRAGON 7C COMPUTE FIRMWARE
Snapdragon 7c Gen 2 Compute Platform ファームウェア
snapdragon xr2 5g ファームウェア
fas…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における複数の脆弱性 CWE-119
CWE-822
CVE-2025-47408 2026-05-8 12:11 2026-05-4 Show GitHub Exploit DB Packet Storm
1294 7.5 重要
Network
ssh2 project ssh2 mscdexのSSH2における非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2025-70034 2026-05-8 12:10 2026-03-9 Show GitHub Exploit DB Packet Storm
1295 6.7 警告
Local
メディアテック MT6789 Firmware
MT6993 Firmware
MT8196 Firmware
MT8367 Firmware
MT6989 Firmware
MT6991 Firmware
MT8766 Firmware
MT8786 Firmware
MT8910&…
メディアテックのMT6768 ファームウェア等の複数製品における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-20447 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
1296 6.7 警告
Local
メディアテック MT8781 Firmware
MT8775 Firmware
MT6765 ファームウェア
MT6789 Firmware
MT8367 Firmware
MT6897 Firmware
MT8796 Firmware
MT6768 ファームウェア
MT6877&nb…
メディアテックのMT6765 ファームウェア等の複数製品における不十分なパーミッションまたは特権の不適切な処理に関する脆弱性 CWE-280
権限管理不備
CVE-2026-20448 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
1297 6.5 警告
Adjacent
メディアテック MT6761 ファームウェア
MT6835 Firmware
MT6858 Firmware
MT8795T Firmware
MT8797 Firmware
MT6855 Firmware
MT6880 Firmware
MT8755 Firmware
MT8668&…
メディアテックのMT2735 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-20449 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
1298 6.5 警告
Adjacent
メディアテック MT6835 Firmware
MT6858 Firmware
MT8795T Firmware
MT8797 Firmware
MT6855 Firmware
MT6880 Firmware
MT8755 Firmware
MT8668 Firmware
MT8678…
メディアテックのMT2735 ファームウェア等の複数製品における到達可能なアサーションに関する脆弱性 CWE-617
到達可能なアサーション
CVE-2026-20450 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
1299 6.7 警告
Local
メディアテック MT8186 Firmware
MT8395 Firmware
MT8678 Firmware
MT8775 Firmware
MT8781 Firmware
MT6985 Firmware
MT8188 Firmware
MT8196 Firmware
MT8367&…
メディアテックのMT2718 Firmware等の複数製品における型の取り違えに関する脆弱性 CWE-843
型の取り違え
CVE-2026-20451 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
1300 7.8 重要
Local
クアルコム QCA6574 ファームウェア
SM6650P ファームウェア
QXM1086 Firmware
SA8150P ファームウェア
QXM1096 Firmware
snapdragon 8 gen 2 mobile ファームウェア
qca6688aq …
クアルコムのAR8031 ファームウェア等の複数製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-24082 2026-05-8 12:10 2026-05-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1291 7.5 HIGH
Network
apple ipados
iphone_os
macos
tvos
visionos
watchos
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26… CWE-121
Stack-based Buffer Overflow
CVE-2026-28846 2026-05-13 22:46 2026-05-12 Show GitHub Exploit DB Packet Storm
1292 6.1 MEDIUM
Network
th30d4y w4nn4d13\/ip In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was direc… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2026-41575 2026-05-13 06:11 2026-05-9 Show GitHub Exploit DB Packet Storm
1293 8.1 HIGH
Network
inducer relate RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. CWE-208
CWE-203
 Information Exposure Through Timing Discrepancy
 Information Exposure Through Discrepancy
CVE-2026-41588 2026-05-13 06:09 2026-05-9 Show GitHub Exploit DB Packet Storm
1294 7.5 HIGH
Network
fohrloop dash-uploader An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload func… NVD-CWE-noinfo
CWE-400
CWE-670
 Uncontrolled Resource Consumption
 Always-Incorrect Control Flow Implementation
CVE-2026-38361 2026-05-13 05:55 2026-05-9 Show GitHub Exploit DB Packet Storm
1295 7.2 HIGH
Network
dolibarr dolibarr_erp\/crm Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerabilit… CWE-74
Injection
CVE-2025-67486 2026-05-13 05:54 2026-05-9 Show GitHub Exploit DB Packet Storm
1296 9.9 CRITICAL
Network
pfsense pfsense Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally all… CWE-284
CWE-915
Improper Access Control
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2025-69691 2026-05-13 05:39 2026-05-8 Show GitHub Exploit DB Packet Storm
1297 7.5 HIGH
Network
vmware spring_cloud_config When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring C… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-40981 2026-05-13 05:34 2026-05-7 Show GitHub Exploit DB Packet Storm
1298 6.1 MEDIUM
Network
naturalintelligence fast-xml-parser fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the … CWE-91
Blind XPath Injection
CVE-2026-41650 2026-05-13 05:30 2026-05-8 Show GitHub Exploit DB Packet Storm
1299 9.8 CRITICAL
Network
snipeitapp snipe-it Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controller… CWE-284
Improper Access Control
CVE-2026-37709 2026-05-13 05:29 2026-05-8 Show GitHub Exploit DB Packet Storm
1300 6.3 MEDIUM
Network
router-for-me cliproxyapi A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-8081 2026-05-13 05:27 2026-05-8 Show GitHub Exploit DB Packet Storm