Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3701 7.5 重要
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-1586 2026-02-4 18:37 2026-01-29 Show GitHub Exploit DB Packet Storm
3702 7.5 重要
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-1587 2026-02-4 18:37 2026-01-29 Show GitHub Exploit DB Packet Storm
3703 9.8 緊急
Network
angeljudesuarez society management system Angel Jude Reyes Suarezのsociety management systemにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-1593 2026-02-4 18:37 2026-01-29 Show GitHub Exploit DB Packet Storm
3704 9.8 緊急
Network
angeljudesuarez society management system Angel Jude Reyes Suarezのsociety management systemにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-1594 2026-02-4 18:37 2026-01-29 Show GitHub Exploit DB Packet Storm
3705 9.8 緊急
Network
angeljudesuarez society management system Angel Jude Reyes Suarezのsociety management systemにおける複数の脆弱性 CWE-74
CWE-89
CVE-2026-1595 2026-02-4 18:37 2026-01-29 Show GitHub Exploit DB Packet Storm
3706 9.1 緊急
Network
サムスン android サムスンのAndroidにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-20973 2026-02-4 18:37 2026-01-9 Show GitHub Exploit DB Packet Storm
3707 4.6 警告
Physics
サムスン android サムスンのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-20974 2026-02-4 18:36 2026-01-9 Show GitHub Exploit DB Packet Storm
3708 7.5 重要
Network
マイクロソフト Microsoft Copilot Studio Copilot Studio の情報漏えいの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-21520 2026-02-4 18:36 2026-01-22 Show GitHub Exploit DB Packet Storm
3709 7.4 重要
Network
マイクロソフト Microsoft 365 Word Copilot Word Copilot Information Disclosure Vulnerability CWE-150
エスケープ、メタ、またはコントロールシーケンスの不適切な無効化
CVE-2026-21521 2026-02-4 18:36 2026-01-22 Show GitHub Exploit DB Packet Storm
3710 6.5 警告
Network
Pterodactyl Wings PterodactylのWingsにおける複数の脆弱性 CWE-400
CWE-770
CVE-2026-21696 2026-02-4 18:36 2026-01-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 7.1 HIGH
Network
- - New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an … New CWE-345
CWE-863
CWE-1188
 Insufficient Verification of Data Authenticity
 Incorrect Authorization
 Insecure Default Initialization of Resource
CVE-2026-41432 2026-05-9 08:16 2026-05-9 Show GitHub Exploit DB Packet Storm
212 9.8 CRITICAL
Network
- - ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. Update CWE-94
Code Injection
CVE-2026-36458 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
213 - - - Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal … Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-32686 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
214 9.8 CRITICAL
Network
- - The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports bot… Update CWE-285
Improper Authorization
CVE-2026-30496 2026-05-9 08:16 2026-05-7 Show GitHub Exploit DB Packet Storm
215 8.8 HIGH
Adjacent
- - The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is con… Update CWE-285
Improper Authorization
CVE-2026-30495 2026-05-9 08:16 2026-05-7 Show GitHub Exploit DB Packet Storm
216 6.1 MEDIUM
Network
- - Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb. Update CWE-79
Cross-site Scripting
CVE-2025-67202 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
217 9.8 CRITICAL
Network
- - NPM package next-npm-version1.0.1 is vulnerable to Command injection. Update CWE-94
Code Injection
CVE-2025-63706 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
218 9.8 CRITICAL
Network
- - npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). Update CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2025-63703 2026-05-9 08:16 2026-05-8 Show GitHub Exploit DB Packet Storm
219 7.5 HIGH
Network
- - Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. New - CVE-2026-42499 2026-05-9 07:16 2026-05-8 Show GitHub Exploit DB Packet Storm
220 - - - Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially… New CWE-89
SQL Injection
CVE-2026-42287 2026-05-9 07:16 2026-05-9 Show GitHub Exploit DB Packet Storm