Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3281 - - struktur AG libheif libheifにおける境界外読み取りの脆弱性 - CVE-2025-65586 2026-01-29 09:47 2026-01-28 Show GitHub Exploit DB Packet Storm
3282 9.8 緊急
Network
Centreon Centreon AWIE CentreonのCentreon AWIEにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-15029 2026-01-28 12:42 2026-01-5 Show GitHub Exploit DB Packet Storm
3283 9.8 緊急
Network
ThemeMove Moody ThemeMoveのWordPress用MoodyにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-22707 2026-01-28 12:42 2026-01-8 Show GitHub Exploit DB Packet Storm
3284 9.8 緊急
Network
ThemeMove Mitech ThemeMoveのWordPress用MitechにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-22708 2026-01-28 12:42 2026-01-8 Show GitHub Exploit DB Packet Storm
3285 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
WCD9385 ファームウェア
WCN3988 ファームウェア
wcn7880 ファームウェア
SXR2330P ファーム…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2025-47388 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
3286 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
WCD9385 ファームウェア
WCN3988 ファームウェア
wcn7880 ファームウェア
SXR2330P ファーム…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2025-47394 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
3287 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
Snapdragon AR1 Gen 1 Platform "Luna1" ファームウェア
W…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2025-47396 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
3288 6.1 警告
Network
Sick
firefly
Package Analytics
Field Analytics
Tire Analytics
media server
Logistics Diagnostic Analytics
Baggage Analytics
SickのBaggage Analytics等の複数製品における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2025-49193 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
3289 7.5 重要
Network
firefly media server SickのMedia Serverにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-49194 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
3290 9.8 緊急
Network
firefly media server SickのMedia Serverにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2025-49195 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
91 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and … New CWE-693
 Protection Mechanism Failure
CVE-2026-26956 2026-05-5 23:16 2026-05-5 Show GitHub Exploit DB Packet Storm
92 4.4 MEDIUM
Local
mercurycom mipc252w_firmware A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-35901 2026-05-5 22:41 2026-04-28 Show GitHub Exploit DB Packet Storm
93 6.2 MEDIUM
Local
mercurycom mipc252w_firmware The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete… Update CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-35902 2026-05-5 22:40 2026-04-28 Show GitHub Exploit DB Packet Storm
94 9.8 CRITICAL
Network
mercurycom mipc252w_firmware MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, … Update CWE-287
Improper Authentication
CVE-2026-35903 2026-05-5 22:39 2026-04-28 Show GitHub Exploit DB Packet Storm
95 7.2 HIGH
Network
- - A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore Endpoint. This manipulatio… New CWE-74
CWE-77
Injection
Command Injection
CVE-2026-7833 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm
96 7.0 HIGH
Local
- - A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attackin… New CWE-59
CWE-61
Link Following
 UNIX Symbolic Link (Symlink) Following
CVE-2026-7832 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm
97 9.6 CRITICAL
Network
- - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability e… New CWE-89
SQL Injection
CVE-2026-42087 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm
98 8.7 HIGH
Network
- - Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulner… New CWE-89
SQL Injection
CVE-2026-35228 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm
99 5.9 MEDIUM
Network
- - eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under… New CWE-302
 Authentication Bypass by Assumed-Immutable Data
CVE-2026-28510 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm
100 5.4 MEDIUM
Network
- - Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper … New CWE-91
Blind XPath Injection
CVE-2026-27693 2026-05-5 22:16 2026-05-5 Show GitHub Exploit DB Packet Storm