Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1841 7.5 重要
Network
オラクル Oracle HCM Common Architecture オラクルのOracle HCM Common Architectureにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-34297 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1842 6.5 警告
Network
オラクル Oracle Financial Services Analytical Applications Infrastructure オラクルのOracle Financial Services Analytical Applications Infrastructureにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-34313 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1843 6.8 警告
Network
オラクル Oracle Financial Services Analytical Applications Infrastructure オラクルのOracle Financial Services Analytical Applications Infrastructureにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-34314 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1844 4.8 警告
Network
オラクル Oracle Financial Services Analytical Applications Infrastructure オラクルのOracle Financial Services Analytical Applications Infrastructureにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-34321 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1845 6.3 警告
Network
オラクル Oracle Life Sciences InForm オラクルのOracle Life Sciences InFormにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-34323 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1846 6.5 警告
Network
オラクル Oracle Life Sciences InForm オラクルのOracle Life Sciences InFormにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-34324 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1847 6.8 警告
Local
オラクル Oracle Financial Services Analytical Applications Infrastructure オラクルのOracle Financial Services Analytical Applications Infrastructureにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-34325 2026-04-27 11:22 2026-04-21 Show GitHub Exploit DB Packet Storm
1848 8.8 重要
Network
jellyfin jellyfin jellyfinにおける複数の脆弱性 CWE-187
CWE-20
CWE-22
CVE-2026-35031 2026-04-27 11:22 2026-04-14 Show GitHub Exploit DB Packet Storm
1849 6.5 警告
Network
jellyfin jellyfin jellyfinにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-35034 2026-04-27 11:22 2026-04-14 Show GitHub Exploit DB Packet Storm
1850 8.8 重要
Network
Glances project Glances Nicolas Hennion (nicolargo)のGlancesにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35587 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1151 9.6 CRITICAL
Network
- - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Py… Update CWE-250
 Execution with Unnecessary Privileges
CVE-2026-42088 2026-05-8 00:05 2026-05-5 Show GitHub Exploit DB Packet Storm
1152 5.3 MEDIUM
Network
flowiseai flowise A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Respo… Update CWE-200
CWE-284
CWE-312
Information Exposure
Improper Access Control
 Cleartext Storage of Sensitive Information
CVE-2026-8026 2026-05-8 00:04 2026-05-6 Show GitHub Exploit DB Packet Storm
1153 5.3 MEDIUM
Network
- - OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from span a… New CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-41310 2026-05-8 00:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1154 5.9 MEDIUM
Network
- - OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM insta… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41483 2026-05-8 00:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1155 5.3 MEDIUM
Adjacent
- - OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collecto… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41484 2026-05-8 00:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1156 - - - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,… New CWE-91
Blind XPath Injection
CVE-2026-41674 2026-05-8 00:02 2026-05-7 Show GitHub Exploit DB Packet Storm
1157 8.8 HIGH
Network
hcltech bigfix_service_management HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses… CWE-200
Information Exposure
CVE-2025-52613 2026-05-7 23:59 2026-05-7 Show GitHub Exploit DB Packet Storm
1158 6.5 MEDIUM
Network
- - Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a trunca… CWE-476
 NULL Pointer Dereference
CVE-2026-41647 2026-05-7 23:59 2026-05-7 Show GitHub Exploit DB Packet Storm
1159 6.5 MEDIUM
Network
- - Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy bac… CWE-476
 NULL Pointer Dereference
CVE-2026-41684 2026-05-7 23:59 2026-05-7 Show GitHub Exploit DB Packet Storm
1160 10.0 CRITICAL
Network
- - Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsani… CWE-88
Argument Injection
CVE-2026-40281 2026-05-7 23:58 2026-05-7 Show GitHub Exploit DB Packet Storm