Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 12:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2611 5.5 警告
Local
Absolute Software secure access Absolute Softwareのsecure accessにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-33452 2026-05-7 11:27 2026-04-30 Show GitHub Exploit DB Packet Storm
2612 9.1 緊急
Network
レッドハット
GNU Project
GnuTLS
Red Hat Enterprise Linux
Red Hat OpenShift Container Platform
GNU Project等の複数ベンダの製品における整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2026-33845 2026-05-7 11:27 2026-04-30 Show GitHub Exploit DB Packet Storm
2613 5.3 警告
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-33857 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
2614 5.3 警告
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける複数の脆弱性 CWE-125
CWE-170
CVE-2026-34032 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
2615 7.5 重要
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-34059 2026-05-7 11:27 2026-05-4 Show GitHub Exploit DB Packet Storm
2616 6.5 警告
Network
SAP human capital management SAPのhuman capital managementにおけるリクエストに対するレスポンス内容の違いに起因する情報漏えいに関する脆弱性 CWE-204
リクエストに対するレスポンス内容の違いに起因する情報漏えい
CVE-2026-34264 2026-05-7 11:27 2026-04-14 Show GitHub Exploit DB Packet Storm
2617 7.5 重要
Network
Go JOSE project Go JOSE Go JOSE projectのGo JOSEにおけるキャッチされない例外に関する脆弱性 CWE-248
キャッチされない例外
CVE-2026-34986 2026-05-7 11:27 2026-04-6 Show GitHub Exploit DB Packet Storm
2618 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける関数の戻り値に対する不適切なチェックに関する脆弱性 CWE-253
関数の戻り値に対する不適切なチェック
CVE-2026-35339 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
2619 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける関数の戻り値に対する不適切なチェックに関する脆弱性 CWE-253
関数の戻り値に対する不適切なチェック
CVE-2026-35340 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
2620 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける安全でない一時ファイルに関する脆弱性 CWE-377
安全でない一時ファイル
CVE-2026-35342 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1921 8.1 HIGH
Network
- - efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk en… CWE-863
 Incorrect Authorization
CVE-2026-44260 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1922 4.6 MEDIUM
Network
- - efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security heade… CWE-80
Basic XSS
CVE-2026-44259 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1923 3.7 LOW
Network
- - Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where th… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-44242 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1924 7.5 HIGH
Network
- - Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, TimeConverterRegistrar caches DateTimeForma… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-44241 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1925 6.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exp… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-44113 2026-05-14 01:16 2026-05-7 Show GitHub Exploit DB Packet Storm
1926 - - - Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user … CWE-479
CVE-2026-44011 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1927 - - - Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filteri… CWE-862
 Missing Authorization
CVE-2026-44010 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1928 9.9 CRITICAL
Network
- - wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object … CWE-863
 Incorrect Authorization
CVE-2026-43948 2026-05-14 01:16 2026-05-13 Show GitHub Exploit DB Packet Storm
1929 6.8 MEDIUM
Network
bx33661 wireshark_mcp Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_expor… CWE-22
Path Traversal
CVE-2026-43901 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm
1930 7.7 HIGH
Network
- - Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken aut… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-43890 2026-05-14 01:16 2026-05-12 Show GitHub Exploit DB Packet Storm