Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4321 5.4 警告
Network
MaxKB MaxKB MaxKBにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-39422 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4322 5.4 警告
Network
MaxKB MaxKB MaxKBにおける複数の脆弱性 CWE-79
CWE-95
CVE-2026-39423 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4323 4.7 警告
Network
MaxKB MaxKB MaxKBにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2026-39424 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4324 5.4 警告
Network
MaxKB MaxKB MaxKBにおけるクロスサイトスクリプティングの脆弱性 CWE-80
クロスサイトスクリプティング (Basic XSS)
CVE-2026-39425 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4325 5.4 警告
Network
MaxKB MaxKB MaxKBにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-39426 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4326 9.8 緊急
Network
フォーティネット FortiSandbox フォーティネットのFortiSandboxにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-39808 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4327 9.8 緊急
Network
フォーティネット FortiSandbox フォーティネットのFortiSandboxにおけるパストラバーサルの脆弱性 CWE-24
パストラバーサル (../filedir)
CVE-2026-39813 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4328 8.8 重要
Network
フォーティネット FortiDDoS-F フォーティネットのFortiDDoS-FにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-39815 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4329 4.3 警告
Network
saleor saleor saleorにおけるリクエストに対するレスポンス内容の違いに起因する情報漏えいに関する脆弱性 CWE-204
リクエストに対するレスポンス内容の違いに起因する情報漏えい
CVE-2026-39851 2026-04-21 10:45 2026-04-8 Show GitHub Exploit DB Packet Storm
4330 5.3 警告
Network
Apostrophe Technologies ApostropheCMS Apostrophe TechnologiesのApostropheCMSにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-39857 2026-04-21 10:45 2026-04-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 10.0 CRITICAL
Network
dhtmlx pdf_export_module PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicio… New CWE-78
OS Command 
CVE-2026-41553 2026-05-19 03:40 2026-05-15 Show GitHub Exploit DB Packet Storm
2 8.7 HIGH
Network
mattermost mattermost_server Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermo… New CWE-200
Information Exposure
CVE-2026-6346 2026-05-19 03:39 2026-05-18 Show GitHub Exploit DB Packet Storm
3 7.6 HIGH
Network
mattermost mattermost_server Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a su… New CWE-200
Information Exposure
CVE-2026-6347 2026-05-19 03:39 2026-05-18 Show GitHub Exploit DB Packet Storm
4 9.8 CRITICAL
Network
radare radare2 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed b… New CWE-416
 Use After Free
CVE-2026-8695 2026-05-19 03:38 2026-05-16 Show GitHub Exploit DB Packet Storm
5 9.8 CRITICAL
Network
radare radare2 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbi… New CWE-416
 Use After Free
CVE-2026-8696 2026-05-19 03:38 2026-05-16 Show GitHub Exploit DB Packet Storm
6 4.3 MEDIUM
Network
mattermost mattermost_server Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, a… New CWE-672
 Operation on a Resource after Expiration or Release
CVE-2026-4053 2026-05-19 03:37 2026-05-16 Show GitHub Exploit DB Packet Storm
7 6.5 MEDIUM
Network
mattermost mattermost_server Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG fi… New CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-4054 2026-05-19 03:36 2026-05-16 Show GitHub Exploit DB Packet Storm
8 6.5 MEDIUM
Network
open5gs open5gs A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool … New CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8731 2026-05-19 03:35 2026-05-17 Show GitHub Exploit DB Packet Storm
9 9.1 CRITICAL
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is no… New CWE-287
NVD-CWE-noinfo
Improper Authentication
CVE-2026-44551 2026-05-19 03:35 2026-05-16 Show GitHub Exploit DB Packet Storm
10 6.5 MEDIUM
Network
open5gs open5gs A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s… New CWE-404
 Improper Resource Shutdown or Release
CVE-2026-8729 2026-05-19 03:35 2026-05-17 Show GitHub Exploit DB Packet Storm