Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1631 - - weintek
Weintek Labs., Inc.
cMT-SVRX-820
cMT3072XH(T)
cMT-CTRL01
cMT3072XH
複数のWeintek製品における複数の脆弱性 CWE-472
CWE-620
CVE-2025-14750
CVE-2025-14751
2026-01-27 12:25 2026-01-26 Show GitHub Exploit DB Packet Storm
1632 - - EVMAPA EVMAPA EVMAPAにおける複数の脆弱性 CWE-306
CWE-307
CWE-613
CVE-2025-53968
CVE-2025-54816
CVE-2025-55705
2026-01-27 12:25 2026-01-26 Show GitHub Exploit DB Packet Storm
1633 - - Hubitat Elevation C7 ファームウェア
Elevation C3 ファームウェア
Elevation C8 pro ファームウェア
Elevation C8 ファームウェア
Elevation C5 ファームウェア
Elevation C4&nb…
Hubitat製Elevation Hubsにおけるユーザー識別情報操作による権限チェック回避の脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-1201 2026-01-27 12:25 2026-01-26 Show GitHub Exploit DB Packet Storm
1634 - - アクシスコミュニケーションズ AXIS Device Manager
AXIS Camera Station
AXIS Camera Station Pro
複数のAxis Communications製品における複数の脆弱性 CWE-288
CWE-295
CWE-502
CVE-2025-30023
CVE-2025-30024
CVE-2025-30025
CVE-2025-30026
2026-01-27 12:25 2026-01-26 Show GitHub Exploit DB Packet Storm
1635 7.3 重要
Local
富士ゼロックス株式会社 beat-access beat-access Windows版におけるDLL読み込みに関する脆弱性 CWE-Other
その他
CVE-2026-21408 2026-01-27 12:07 2026-01-27 Show GitHub Exploit DB Packet Storm
1636 9.1 緊急
Network
Sick SICK TDC-X401GL Firmware SickのSICK TDC-X401GL Firmwareにおける不適切な権限設定に関する脆弱性 CWE-266
CWE-noinfo
CVE-2026-22908 2026-01-26 19:43 2026-01-15 Show GitHub Exploit DB Packet Storm
1637 9.1 緊急
Network
Sick SICK TDC-X401GL Firmware SickのSICK TDC-X401GL Firmwareにおける複数の脆弱性 CWE-284
CWE-863
CVE-2026-22909 2026-01-26 19:43 2026-01-15 Show GitHub Exploit DB Packet Storm
1638 9.1 緊急
Network
Sick SICK TDC-X401GL Firmware SickのSICK TDC-X401GL Firmwareにおける弱い認証情報の使用に関する脆弱性 CWE-1391
脆弱な認証情報の使用
CVE-2026-22910 2026-01-26 19:43 2026-01-15 Show GitHub Exploit DB Packet Storm
1639 7.5 重要
Network
Sick SICK TDC-X401GL Firmware SickのSICK TDC-X401GL Firmwareにおける複数の脆弱性 CWE-522
CWE-798
CVE-2026-22911 2026-01-26 19:43 2026-01-15 Show GitHub Exploit DB Packet Storm
1640 6.1 警告
Network
Sick SICK TDC-X401GL Firmware SickのSICK TDC-X401GL Firmwareにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-22912 2026-01-26 19:43 2026-01-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
131 5.4 MEDIUM
Network
b3log siyuan SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTM… Update CWE-79
Cross-site Scripting
CVE-2026-40922 2026-04-21 01:16 2026-04-17 Show GitHub Exploit DB Packet Storm
132 - - - radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in… Update CWE-78
OS Command 
CVE-2026-40499 2026-04-21 01:16 2026-04-15 Show GitHub Exploit DB Packet Storm
133 8.9 HIGH
Network
- - Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to t… Update CWE-79
CWE-345
CWE-434
Cross-site Scripting
 Insufficient Verification of Data Authenticity
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-40487 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm
134 9.3 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with… Update CWE-20
CWE-269
 Improper Input Validation 
 Improper Privilege Management
CVE-2026-40317 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm
135 - - - free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating Traffic Influence Subscriptions checks whether th… Update CWE-285
CWE-636
Improper Authorization
 Not Failing Securely ('Failing Open')
CVE-2026-40248 2026-04-21 01:16 2026-04-17 Show GitHub Exploit DB Packet Storm
136 7.5 HIGH
Network
- - ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack bu… Update CWE-121
Stack-based Buffer Overflow
CVE-2026-40170 2026-04-21 01:16 2026-04-17 Show GitHub Exploit DB Packet Storm
137 5.3 MEDIUM
Network
- - Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By defau… New CWE-533
CVE-2026-33558 2026-04-21 01:16 2026-04-20 Show GitHub Exploit DB Packet Storm
138 9.1 CRITICAL
Network
- - A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.… New CWE-1285
 Improper Validation of Specified Index, Position, or Offset in Input
CVE-2026-33557 2026-04-21 01:16 2026-04-20 Show GitHub Exploit DB Packet Storm
139 4.8 MEDIUM
Network
- - Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass t… Update CWE-305
CWE-319
 Authentication Bypass by Primary Weakness
Cleartext Transmission of Sensitive Information
CVE-2026-33472 2026-04-21 01:16 2026-04-17 Show GitHub Exploit DB Packet Storm
140 7.5 HIGH
Network
- - UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Update CWE-863
 Incorrect Authorization
CVE-2026-32228 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm