Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2451 7.1 重要
Local
ブロケード コミュニケーションズ システムズ株式会社 ASCG ブロケード コミュニケーションズ システムズ株式会社のASCGにおける重要な情報の平文保存に関する脆弱性 CWE-312
重要な情報の平文保存
CVE-2025-7397 2026-02-4 18:41 2025-07-17 Show GitHub Exploit DB Packet Storm
2452 9.1 緊急
Network
ブロケード コミュニケーションズ システムズ株式会社 ASCG ブロケード コミュニケーションズ システムズ株式会社のASCGにおける暗号強度に関する脆弱性 CWE-326
不適切な暗号強度
CVE-2025-7398 2026-02-4 18:41 2025-07-17 Show GitHub Exploit DB Packet Storm
2453 9.8 緊急
Network
angeljudesuarez School Management System Project In PHP Source Code Angel Jude Reyes SuarezのSchool Management System Project In PHP Source Codeにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-1545 2026-02-4 18:40 2026-01-28 Show GitHub Exploit DB Packet Storm
2454 5.3 警告
Network
Project-monai MONAI Project-monaiのMONAIにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-21851 2026-02-4 18:40 2026-01-7 Show GitHub Exploit DB Packet Storm
2455 5.3 警告
Network
Ralph Slooten Mailpit Ralph SlootenのMailpitにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-21859 2026-02-4 18:40 2026-01-8 Show GitHub Exploit DB Packet Storm
2456 9.8 緊急
Network
Bluspark BLUVOYIX BlusparkのBLUVOYIXにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-22236 2026-02-4 18:40 2026-01-14 Show GitHub Exploit DB Packet Storm
2457 9.8 緊急
Network
Bluspark BLUVOYIX BlusparkのBLUVOYIXにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-22237 2026-02-4 18:40 2026-01-14 Show GitHub Exploit DB Packet Storm
2458 9.8 緊急
Network
Bluspark BLUVOYIX BlusparkのBLUVOYIXにおける複数の脆弱性 CWE-269
CWE-306
CVE-2026-22238 2026-02-4 18:40 2026-01-14 Show GitHub Exploit DB Packet Storm
2459 5.3 警告
Network
Bluspark BLUVOYIX BlusparkのBLUVOYIXにおけるリソースの枯渇に関する脆弱性 CWE-400
CWE-noinfo
CVE-2026-22239 2026-02-4 18:40 2026-01-14 Show GitHub Exploit DB Packet Storm
2460 7.5 重要
Network
Bluspark BLUVOYIX BlusparkのBLUVOYIXにおける複数の脆弱性 CWE-200
CWE-312
CWE-522
CWE-522
CVE-2026-22240 2026-02-4 18:40 2026-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
691 7.2 HIGH
Network
apache neethi Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a poli… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42404 2026-05-2 03:06 2026-05-1 Show GitHub Exploit DB Packet Storm
692 9.8 CRITICAL
Network
apache mina The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inc… CWE-502
 Deserialization of Untrusted Data
CVE-2026-42778 2026-05-2 02:55 2026-05-1 Show GitHub Exploit DB Packet Storm
693 9.8 CRITICAL
Network
apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, on… CWE-502
 Deserialization of Untrusted Data
CVE-2026-42779 2026-05-2 02:55 2026-05-1 Show GitHub Exploit DB Packet Storm
694 5.9 MEDIUM
Network
apache airflow Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between … CWE-295
Improper Certificate Validation 
CVE-2026-41016 2026-05-2 02:54 2026-04-30 Show GitHub Exploit DB Packet Storm
695 9.6 CRITICAL
Network
mozilla firefox
thunderbird
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1. CWE-120
Classic Buffer Overflow
CVE-2026-7321 2026-05-2 02:54 2026-04-29 Show GitHub Exploit DB Packet Storm
696 5.3 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2025-14688 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
697 6.5 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially cra… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2025-36122 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
698 6.5 MEDIUM
Network
ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-1577 2026-05-2 02:52 2026-05-1 Show GitHub Exploit DB Packet Storm
699 9.8 CRITICAL
Network
exim exim In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation… CWE-684
CWE-787
 Incorrect Provision of Specified Functionality
 Out-of-bounds Write
CVE-2026-40685 2026-05-2 02:51 2026-05-1 Show GitHub Exploit DB Packet Storm
700 5.5 MEDIUM
Local
opencascade open_cascade_technology An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML… CWE-125
Out-of-bounds Read
CVE-2026-42479 2026-05-2 02:48 2026-05-2 Show GitHub Exploit DB Packet Storm