Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2901 9.8 緊急
Network
HzManyun Education and Training System HzManyunのEducation and Training Systemにおける複数の脆弱性 CWE-74
CWE-77
CWE-77
CVE-2025-1947 2026-02-2 19:26 2025-03-4 Show GitHub Exploit DB Packet Storm
2902 4.6 警告
Physics
サムスン Gallery サムスンのGalleryにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-20966 2026-02-2 19:26 2025-05-7 Show GitHub Exploit DB Packet Storm
2903 9.1 緊急
Network
サムスン Gallery サムスンのGalleryにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-20967 2026-02-2 19:26 2025-05-7 Show GitHub Exploit DB Packet Storm
2904 9.1 緊急
Network
サムスン Gallery サムスンのGalleryにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-20968 2026-02-2 19:26 2025-05-7 Show GitHub Exploit DB Packet Storm
2905 5.5 警告
Local
サムスン Gallery サムスンのGalleryにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-20969 2026-02-2 19:26 2025-05-7 Show GitHub Exploit DB Packet Storm
2906 4.7 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2025-21746 2026-02-2 19:26 2025-02-27 Show GitHub Exploit DB Packet Storm
2907 9.1 緊急
Network
Imagination Technologies Limited GPU DDK Imagination Technologies LimitedのGPU DDKにおける誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2025-25176 2026-02-2 19:26 2026-01-13 Show GitHub Exploit DB Packet Storm
2908 7.3 重要
Local
DigitalDruid.Net HotelDruid DigitalDruid.NetのHotelDruidにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2025-25748 2026-02-2 19:26 2025-03-11 Show GitHub Exploit DB Packet Storm
2909 7.5 重要
Network
GraphicsMagick GraphicsMagick GraphicsMagickにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-27795 2026-02-2 19:26 2025-03-7 Show GitHub Exploit DB Packet Storm
2910 9.8 緊急
Network
GraphicsMagick GraphicsMagick GraphicsMagickにおける初期化されていないリソースの使用に関する脆弱性 CWE-908
初期化されていないリソースの使用
CVE-2025-27796 2026-02-2 19:26 2025-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
461 4.3 MEDIUM
Network
- - A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the compon… New CWE-404
CWE-476
 Improper Resource Shutdown or Release
 NULL Pointer Dereference
CVE-2026-7701 2026-05-4 01:15 2026-05-4 Show GitHub Exploit DB Packet Storm
462 6.3 MEDIUM
Network
- - A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterC… New CWE-74
CWE-94
Injection
Code Injection
CVE-2026-7700 2026-05-4 00:15 2026-05-4 Show GitHub Exploit DB Packet Storm
463 6.3 MEDIUM
Network
- - A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argum… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7699 2026-05-4 00:15 2026-05-4 Show GitHub Exploit DB Packet Storm
464 7.3 HIGH
Network
- - A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo.… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-7698 2026-05-3 23:16 2026-05-3 Show GitHub Exploit DB Packet Storm
465 4.7 MEDIUM
Network
- - A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file /manager/card/cardhand_submit.php. This manipulation of the argument ID causes… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7697 2026-05-3 23:16 2026-05-3 Show GitHub Exploit DB Packet Storm
466 6.3 MEDIUM
Network
- - A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. T… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-7696 2026-05-3 22:16 2026-05-3 Show GitHub Exploit DB Packet Storm
467 7.3 HIGH
Network
- - A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinA… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7695 2026-05-3 22:16 2026-05-3 Show GitHub Exploit DB Packet Storm
468 7.3 HIGH
Network
- - A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMi… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7694 2026-05-3 21:15 2026-05-3 Show GitHub Exploit DB Packet Storm
469 6.3 MEDIUM
Network
- - A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS re… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-7692 2026-05-3 20:16 2026-05-3 Show GitHub Exploit DB Packet Storm
470 6.3 MEDIUM
Network
- - A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command lea… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-7691 2026-05-3 20:16 2026-05-3 Show GitHub Exploit DB Packet Storm