Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4291 8.1 重要
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-34941 2026-04-21 10:47 2026-04-9 Show GitHub Exploit DB Packet Storm
4292 6.5 警告
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおける配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2026-34942 2026-04-21 10:46 2026-04-9 Show GitHub Exploit DB Packet Storm
4293 7.5 重要
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおけるキャッチされない例外に関する脆弱性 CWE-248
キャッチされない例外
CVE-2026-34943 2026-04-21 10:46 2026-04-9 Show GitHub Exploit DB Packet Storm
4294 5.7 警告
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおけるキャッチされない例外に関する脆弱性 CWE-248
キャッチされない例外
CVE-2026-34944 2026-04-21 10:46 2026-04-9 Show GitHub Exploit DB Packet Storm
4295 6.5 警告
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおける数値型間の変換の誤りに関する脆弱性 CWE-681
数値型間の変換の誤り
CVE-2026-34945 2026-04-21 10:46 2026-04-9 Show GitHub Exploit DB Packet Storm
4296 7.5 重要
Network
Bytecode Alliance wasmtime Bytecode Allianceのwasmtimeにおける常に不適切な制御フローの実装に関する脆弱性 CWE-670
常に不適切な制御フローの実装
CVE-2026-34946 2026-04-21 10:46 2026-04-9 Show GitHub Exploit DB Packet Storm
4297 8.8 重要
Network
OpenFGA OpenFGA
Helm Charts
OpenFGAのHelm Charts等の複数製品における不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-34972 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4298 9.8 緊急
Network
man d-tale Man GroupのD-Taleにおけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-noinfo
CVE-2026-35052 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4299 5.4 警告
Network
GoHugo Hugo GoHugoのHugoにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-35166 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4300 6.5 警告
Network
Eugene Pankov Ajenti Eugene PankovのAjentiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-35175 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
61 6.2 MEDIUM
Local
- - ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send req… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2021-47978 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
62 7.5 HIGH
Network
- - WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the f… New CWE-22
Path Traversal
CVE-2021-47977 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
63 8.8 HIGH
Network
- - TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can… New CWE-352
 Origin Validation Error
CVE-2021-47976 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
64 7.2 HIGH
Network
- - WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit PO… New CWE-79
Cross-site Scripting
CVE-2021-47975 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
65 7.8 HIGH
Local
- - VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place ma… New CWE-428
 Unquoted Search Path or Element
CVE-2021-47974 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
66 7.5 HIGH
Network
- - Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can gener… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2021-47973 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
67 7.5 HIGH
Network
- - Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can p… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2021-47972 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
68 7.5 HIGH
Network
- - My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a pa… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2021-47971 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
69 7.5 HIGH
Network
- - Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2021-47970 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm
70 7.5 HIGH
Network
- - Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payl… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2021-47969 2026-05-17 01:16 2026-05-17 Show GitHub Exploit DB Packet Storm