Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3711 7.5 重要
Network
oneflow oneflow oneflowにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65886 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3712 6.5 警告
Network
oneflow oneflow oneflowにおけるゼロ除算に関する脆弱性 CWE-369
ゼロ除算
CVE-2025-65887 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3713 7.5 重要
Network
oneflow oneflow oneflowにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65888 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3714 7.5 重要
Network
oneflow oneflow oneflowにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65889 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3715 7.5 重要
Network
oneflow oneflow oneflowにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65890 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3716 7.5 重要
Network
oneflow oneflow oneflowにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65891 2026-02-5 15:45 2026-01-28 Show GitHub Exploit DB Packet Storm
3717 7.5 重要
Network
Quarkus Quarkus Quarkusにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-66560 2026-02-5 15:45 2026-01-7 Show GitHub Exploit DB Packet Storm
3718 9.8 緊急
Network
Fabian Ros Mobile Shop Management System In PHP With Source Code Fabian RosのMobile Shop Management System In PHP With Source CodeにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-69562 2026-02-5 15:45 2026-01-27 Show GitHub Exploit DB Packet Storm
3719 9.8 緊急
Network
Fabian Ros Mobile Shop Management System In PHP With Source Code Fabian RosのMobile Shop Management System In PHP With Source CodeにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-69563 2026-02-5 15:45 2026-01-27 Show GitHub Exploit DB Packet Storm
3720 9.8 緊急
Network
Fabian Ros Mobile Shop Management System In PHP With Source Code Fabian RosのMobile Shop Management System In PHP With Source Codeにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2025-69565 2026-02-5 15:45 2026-01-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
471 8.2 HIGH
Network
- - Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42260 2026-05-13 00:16 2026-05-13 Show GitHub Exploit DB Packet Storm
472 7.3 HIGH
Network
- - D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection. New CWE-77
Command Injection
CVE-2026-36983 2026-05-13 00:16 2026-05-12 Show GitHub Exploit DB Packet Storm
473 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel … New CWE-89
SQL Injection
CVE-2026-32687 2026-05-13 00:16 2026-05-13 Show GitHub Exploit DB Packet Storm
474 6.8 MEDIUM
Network
- - Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_expor… New CWE-22
Path Traversal
CVE-2026-43901 2026-05-13 00:15 2026-05-12 Show GitHub Exploit DB Packet Storm
475 4.3 MEDIUM
Network
- - Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpoint uses String.startsWith() to validate that a resolved file path is within a … New CWE-22
Path Traversal
CVE-2026-42885 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm
476 - - - Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without suf… New CWE-22
Path Traversal
CVE-2026-42888 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm
477 6.4 MEDIUM
Network
- - WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST parameter and passes it into sendSiteEmail(), which s… New CWE-79
Cross-site Scripting
CVE-2026-43876 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm
478 5.4 MEDIUM
Network
- - WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notification webhook URL to point at internal/loopback/metad… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-43879 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm
479 4.3 MEDIUM
Network
- - WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and jo… New CWE-93
CRLF Injection
CVE-2026-43882 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm
480 - - - WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints… New CWE-200
CWE-862
Information Exposure
 Missing Authorization
CVE-2026-43885 2026-05-13 00:13 2026-05-12 Show GitHub Exploit DB Packet Storm