Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2481 8.8 重要
Adjacent
Linux Linux Kernel LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-31570 2026-04-30 12:09 2026-04-24 Show GitHub Exploit DB Packet Storm
2482 6.1 警告
Network
CyberPanel CyberPanel CyberPanelにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41472 2026-04-30 12:08 2026-04-24 Show GitHub Exploit DB Packet Storm
2483 9.1 緊急
Network
CyberPanel CyberPanel CyberPanelにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-41473 2026-04-30 12:08 2026-04-24 Show GitHub Exploit DB Packet Storm
2484 8.2 重要
Local
レッドハット Red Hat Advanced Cluster Management for Kubernetes レッドハットのRed Hat Advanced Cluster Management for Kubernetesにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-4740 2026-04-30 12:08 2026-04-7 Show GitHub Exploit DB Packet Storm
2485 9.8 緊急
Network
Pipecat Pipecat Pipecatにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-62373 2026-04-30 12:08 2026-04-23 Show GitHub Exploit DB Packet Storm
2486 7.8 重要
Local
Amazon.com, Inc. Kiro IDE Amazon.com, Inc.のKiro IDEにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-0830 2026-04-30 12:08 2026-01-9 Show GitHub Exploit DB Packet Storm
2487 5.4 警告
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-25720 2026-04-30 12:08 2026-04-24 Show GitHub Exploit DB Packet Storm
2488 9.8 緊急
Network
huggingface LeRobot huggingfaceのLeRobotにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-25874 2026-04-30 12:08 2026-04-23 Show GitHub Exploit DB Packet Storm
2489 8.1 重要
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-27841 2026-04-30 12:08 2026-04-24 Show GitHub Exploit DB Packet Storm
2490 9.1 緊急
Network
SenseLive X3500 Firmware SenseLiveのX3500 Firmwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-27843 2026-04-30 12:08 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1771 6.5 MEDIUM
Network
apache apache-airflow-providers-opensearch The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embed… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-43826 2026-05-13 23:05 2026-05-11 Show GitHub Exploit DB Packet Storm
1772 7.5 HIGH
Network
apple ipados
iphone_os
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denia… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-28872 2026-05-13 23:03 2026-05-12 Show GitHub Exploit DB Packet Storm
1773 7.5 HIGH
Network
apple ipados
iphone_os
macos
visionos
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5,… CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-28906 2026-05-13 23:03 2026-05-12 Show GitHub Exploit DB Packet Storm
1774 3.3 LOW
Local
apple macos This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files. CWE-284
Improper Access Control
CVE-2026-28910 2026-05-13 23:02 2026-05-12 Show GitHub Exploit DB Packet Storm
1775 5.4 MEDIUM
Network
apple ipados
iphone_os
macos
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may … CWE-787
 Out-of-bounds Write
CVE-2026-28819 2026-05-13 23:00 2026-05-12 Show GitHub Exploit DB Packet Storm
1776 6.5 MEDIUM
Network
apple ipados
iphone_os
macos
tvos
visionos
watchos
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a malicio… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2026-28918 2026-05-13 22:57 2026-05-12 Show GitHub Exploit DB Packet Storm
1777 9.8 CRITICAL
Network
gnu
redhat
gnutls
hardened_images
openshift_container_platform
enterprise_linux
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacke… CWE-626
 Null Byte Interaction Error (Poison Null Byte)
CVE-2026-42010 2026-05-13 22:54 2026-05-7 Show GitHub Exploit DB Packet Storm
1778 7.5 HIGH
Network
apple ipados
iphone_os
macos
tvos
visionos
watchos
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26… CWE-121
Stack-based Buffer Overflow
CVE-2026-28846 2026-05-13 22:46 2026-05-12 Show GitHub Exploit DB Packet Storm
1779 6.1 MEDIUM
Network
th30d4y w4nn4d13\/ip In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was direc… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2026-41575 2026-05-13 06:11 2026-05-9 Show GitHub Exploit DB Packet Storm
1780 8.1 HIGH
Network
inducer relate RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. CWE-208
CWE-203
 Information Exposure Through Timing Discrepancy
 Information Exposure Through Discrepancy
CVE-2026-41588 2026-05-13 06:09 2026-05-9 Show GitHub Exploit DB Packet Storm