Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3221 5.3 警告
Network
franklioxygen MyTube franklioxygenのMyTubeにおける動的に決定されたオブジェクト属性の不適切に制御された変更に関する脆弱性 CWE-915
動的に決定されたオブジェクト属性の不適切に制御された変更
CVE-2026-24140 2026-02-4 18:40 2026-01-24 Show GitHub Exploit DB Packet Storm
3222 6.1 警告
Network
butor team
Ghost Foundation
Ghost
Portal
Ghost FoundationのGhost等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-24778 2026-02-4 18:40 2026-01-27 Show GitHub Exploit DB Packet Storm
3223 5.4 警告
Network
OpenEMR OpenEMR OpenEMRにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-47817 2026-02-4 18:40 2026-01-21 Show GitHub Exploit DB Packet Storm
3224 5.4 警告
Network
Commvault Systems, Inc Commvault Commvault Systems, IncのCommvaultにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-12776 2026-02-4 18:40 2026-01-7 Show GitHub Exploit DB Packet Storm
3225 7.5 重要
Network
Html2Pdf project Html2Pdf Apryse Software Inc.のHTML2PDFにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2025-56589 2026-02-4 18:40 2026-01-22 Show GitHub Exploit DB Packet Storm
3226 8.8 重要
Network
ZwiiCMS ZwiiCMS ZwiiCMSにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-57130 2026-02-4 18:40 2025-11-5 Show GitHub Exploit DB Packet Storm
3227 5.4 警告
Network
The Starware WorklogPRO The StarwareのWorklogPROにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-57681 2026-02-4 18:40 2026-01-21 Show GitHub Exploit DB Packet Storm
3228 7.5 重要
Network
ollama ollama ollamaにおける複数の脆弱性 CWE-20
CWE-400
CVE-2025-66959 2026-02-4 18:40 2026-01-21 Show GitHub Exploit DB Packet Storm
3229 7.5 重要
Network
ollama ollama ollamaにおける複数の脆弱性 CWE-20
CWE-400
CVE-2025-66960 2026-02-4 18:40 2026-01-21 Show GitHub Exploit DB Packet Storm
3230 7.5 重要
Network
Absolute Software secure access Absolute Softwareのsecure accessにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-0517 2026-02-4 18:40 2026-01-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
421 - - - In the Linux kernel, the following vulnerability has been resolved: comedi: Reinit dev->spinlock between attachments to low-level drivers `struct comedi_device` is the main controlling structure fo… New - CVE-2026-43340 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
422 - - - In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UaF in addrconf_permanent_addr() The mentioned helper try to warn the user about an exceptional condition,… New - CVE-2026-43339 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
423 - - - In the Linux kernel, the following vulnerability has been resolved: btrfs: reserve enough transaction items for qgroup ioctls Currently our qgroup ioctls don't reserve any space, they just do a tra… New - CVE-2026-43338 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
424 - - - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() dcn401_init_hw() assumes that update_bw_bounding_box() is valid… New - CVE-2026-43337 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
425 - - - In the Linux kernel, the following vulnerability has been resolved: lib/crypto: chacha: Zeroize permuted_state before it leaves scope Since the ChaCha permutation is invertible, the local variable … New - CVE-2026-43336 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
426 - - - In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: sm8450: Fix NULL pointer dereference in icc_link_nodes() The change to dynamic IDs for SM8450 platform interc… New - CVE-2026-43335 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
427 - - - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements before building the pairing response smp_cmd_pairing_req() currently builds the… New - CVE-2026-43334 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
428 - - - In the Linux kernel, the following vulnerability has been resolved: bpf: reject direct access to nullable PTR_TO_BUF pointers check_mem_access() matches PTR_TO_BUF via base_type() which strips PTR_… New - CVE-2026-43333 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
429 - - - In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone device registration error path If thermal_zone_device_register_with_trips() fails after registeri… New - CVE-2026-43332 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm
430 - - - In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin… New - CVE-2026-43331 2026-05-8 23:16 2026-05-8 Show GitHub Exploit DB Packet Storm