Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3021 7.8 重要
Local
PY Software. Active WebCam PY Software.のActive WebCamにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2021-47790 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3022 7.8 重要
Local
Remote Mouse Remote Mouse Remote Mouseにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2021-47792 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3023 7.8 重要
Local
Flexense Ltd. DupScout Flexense Ltd.のDupScoutにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2021-47806 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3024 7.8 重要
Local
Flexense Ltd. SyncBreeze Flexense Ltd.のSyncBreezeにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2021-47807 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3025 7.8 重要
Local
Flexense Ltd. DiskSorter Flexense Ltd.のDiskSorterにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2021-47809 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3026 9.1 緊急
Network
Grocery CRUD Grocery CRUD Grocery CRUDにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2021-47811 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3027 7.5 重要
Network
Nsasoft US LLC. NBMonitor Nsasoft US LLC.のNBMonitorにおける古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2021-47814 2026-02-2 19:21 2026-01-16 Show GitHub Exploit DB Packet Storm
3028 5.4 警告
Network
TAGSTOO TAGSTOO TAGSTOOにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-47843 2026-02-2 19:21 2026-01-15 Show GitHub Exploit DB Packet Storm
3029 7.8 重要
Local
ヒューレット・パッカード HP Prodesk 405 G6 Small Form Factor PC Firmware
HP Probook 11 EE G2 Firmware
HP mt20 Mobile Thin Client …
ヒューレット・パッカードのHP Dragonfly Folio 13.5 inch G3 2-in-1 Notebook PC Firmware等の複数製品におけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2022-27540 2026-02-2 19:21 2024-06-28 Show GitHub Exploit DB Packet Storm
3030 9.8 緊急
Network
Tdarr Tdarr TdarrにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2022-50919 2026-02-2 19:21 2026-01-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
81 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM… New CWE-94
CWE-693
Code Injection
 Protection Mechanism Failure
CVE-2026-24120 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
82 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and… New CWE-94
CWE-693
Code Injection
 Protection Mechanism Failure
CVE-2026-24118 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
83 7.8 HIGH
Local
- - Memory Corruption when copying data from a freed source while executing performance counter deselect operation. New CWE-416
 Use After Free
CVE-2026-24082 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
84 7.8 HIGH
Local
- - Memory corruption when another driver calls an IOCTL with invalid input/output buffer. New CWE-822
 Untrusted Pointer Dereference
CVE-2025-47408 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
85 7.8 HIGH
Local
- - Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. New CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2025-47407 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
86 6.1 MEDIUM
Local
- - Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. New CWE-126
 Buffer Over-read
CVE-2025-47406 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
87 7.8 HIGH
Local
- - Memory corruption when processing camera sensor input/output control codes with invalid output buffers. New CWE-822
 Untrusted Pointer Dereference
CVE-2025-47405 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
88 6.5 MEDIUM
Local
- - Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. New CWE-120
Classic Buffer Overflow
CVE-2025-47404 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
89 6.5 MEDIUM
Adjacent
- - Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. New CWE-126
 Buffer Over-read
CVE-2025-47403 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm
90 6.5 MEDIUM
Adjacent
- - Transient DOS when processing target power rate tables during channel configuration. New CWE-126
 Buffer Over-read
CVE-2025-47401 2026-05-5 02:16 2026-05-5 Show GitHub Exploit DB Packet Storm