Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193591 7.5 重要
Network
フォーティネット - Fortinet FortiPortal におけるパスワード管理機能に関する脆弱性 CWE-640
パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み
CVE-2017-7731 2017-06-20 16:33 2017-05-15 Show GitHub Exploit DB Packet Storm
193592 6.1 警告
Network
フォーティネット - Fortinet FortiPortal におけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2017-7343 2017-06-20 16:33 2017-05-15 Show GitHub Exploit DB Packet Storm
193593 6.1 警告
Network
フォーティネット - Fortinet FortiPortal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-7339 2017-06-20 16:33 2017-05-15 Show GitHub Exploit DB Packet Storm
193594 7.5 重要
Network
フォーティネット - Fortinet FortiPortal における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2017-7338 2017-06-20 16:33 2017-05-15 Show GitHub Exploit DB Packet Storm
193595 9.1 緊急
Network
フォーティネット - Fortinet FortiPortal におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-7337 2017-06-20 16:33 2017-05-15 Show GitHub Exploit DB Packet Storm
193596 7.8 重要
Local
pngquant - pngquant の rwpng.c の rwpng_read_image24_libpng 関数における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2016-5735 2017-06-20 16:27 2016-06-24 Show GitHub Exploit DB Packet Storm
193597 6.1 警告
Network
IBM - IBM iNotes におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-1325 2017-06-20 16:27 2017-05-23 Show GitHub Exploit DB Packet Storm
193598 5.3 警告
Network
IBM - IBM Maximo Asset Management における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2017-1292 2017-06-20 16:27 2017-05-23 Show GitHub Exploit DB Packet Storm
193599 5.4 警告
Network
IBM - IBM Maximo Asset Management におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-1291 2017-06-20 16:27 2017-05-23 Show GitHub Exploit DB Packet Storm
193600 6.1 警告
Network
Redmine - Redmine におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8477 2017-06-20 16:20 2015-02-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1831 6.5 MEDIUM
Network
php php In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, re… CWE-476
 NULL Pointer Dereference
CVE-2026-7259 2026-05-13 02:40 2026-05-10 Show GitHub Exploit DB Packet Storm
1832 9.8 CRITICAL
Network
php php In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acr… CWE-416
 Use After Free
CVE-2026-7261 2026-05-13 02:40 2026-05-10 Show GitHub Exploit DB Packet Storm
1833 7.5 HIGH
Network
php php In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which check… CWE-476
 NULL Pointer Dereference
CVE-2026-7262 2026-05-13 02:39 2026-05-10 Show GitHub Exploit DB Packet Storm
1834 7.5 HIGH
Network
php php In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the cur… CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2026-7568 2026-05-13 02:38 2026-05-10 Show GitHub Exploit DB Packet Storm
1835 7.5 HIGH
Network
open5gs open5gs A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation … CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8225 2026-05-13 02:38 2026-05-10 Show GitHub Exploit DB Packet Storm
1836 7.5 HIGH
Network
open5gs open5gs A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8226 2026-05-13 02:38 2026-05-10 Show GitHub Exploit DB Packet Storm
1837 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypTy… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8229 2026-05-13 02:37 2026-05-10 Show GitHub Exploit DB Packet Storm
1838 8.8 HIGH
Network
wavlink wl-nu516u1_firmware A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-8230 2026-05-13 02:37 2026-05-10 Show GitHub Exploit DB Packet Storm
1839 9.1 CRITICAL
Network
php php In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectl… CWE-125
Out-of-bounds Read
CVE-2026-6104 2026-05-13 02:35 2026-05-10 Show GitHub Exploit DB Packet Storm
1840 7.5 HIGH
Network
php php In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu… CWE-404
CWE-835
 Improper Resource Shutdown or Release
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-7263 2026-05-13 02:35 2026-05-10 Show GitHub Exploit DB Packet Storm