Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 2:21 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2911 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2022-50527 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2912 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2022-50528 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2913 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける二重解放に関する脆弱性 CWE-415
二重解放
CVE-2022-50536 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2914 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2022-50537 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2915 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2022-50538 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2916 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-Other
その他
CVE-2022-50539 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2917 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2022-50540 2026-02-6 10:39 2025-10-7 Show GitHub Exploit DB Packet Storm
2918 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2022-50541 2026-02-6 10:38 2025-10-7 Show GitHub Exploit DB Packet Storm
2919 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2022-50542 2026-02-6 10:38 2025-10-7 Show GitHub Exploit DB Packet Storm
2920 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける二重解放に関する脆弱性 CWE-415
二重解放
CVE-2022-50543 2026-02-6 10:38 2025-10-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
641 7.5 HIGH
Network
n8n n8n n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-42236 2026-05-7 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
642 8.8 HIGH
Network
n8n n8n n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype … New CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-42232 2026-05-7 02:15 2026-05-5 Show GitHub Exploit DB Packet Storm
643 8.8 HIGH
Network
n8n n8n n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prot… New CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-42231 2026-05-7 02:14 2026-05-5 Show GitHub Exploit DB Packet Storm
644 7.5 HIGH
Network
miyagawa starman Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both hea… Update CWE-444
HTTP Request Smuggling
CVE-2026-40560 2026-05-7 01:35 2026-04-29 Show GitHub Exploit DB Packet Storm
645 4.3 MEDIUM
Network
jenkins script_security A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths. Update CWE-862
 Missing Authorization
CVE-2026-42519 2026-05-7 01:33 2026-04-29 Show GitHub Exploit DB Packet Storm
646 7.5 HIGH
Network
jenkins credentials_binding Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write file… Update CWE-22
Path Traversal
CVE-2026-42520 2026-05-7 01:32 2026-04-29 Show GitHub Exploit DB Packet Storm
647 6.5 MEDIUM
Network
jenkins matrix_authorization_strategy Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategi… Update CWE-502
 Deserialization of Untrusted Data
CVE-2026-42521 2026-05-7 01:21 2026-04-29 Show GitHub Exploit DB Packet Storm
648 4.3 MEDIUM
Network
jenkins github_branch_source A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacke… Update CWE-862
 Missing Authorization
CVE-2026-42522 2026-05-7 01:18 2026-04-29 Show GitHub Exploit DB Packet Storm
649 8.4 HIGH
Local
hmbrand text\ Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, get… Update CWE-416
CWE-825
 Use After Free
 Expired Pointer Dereference
CVE-2026-7111 2026-05-7 01:16 2026-04-30 Show GitHub Exploit DB Packet Storm
650 8.8 HIGH
Network
redis redis Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to exe… New CWE-122
Heap-based Buffer Overflow
CVE-2026-25243 2026-05-7 01:16 2026-05-6 Show GitHub Exploit DB Packet Storm