Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
431 8.4 重要
Local
マイクロソフト Microsoft Office
Office Long Term Servicing Channel (LTSC)
Microsoft 365 Apps
Microsoft SharePoint Server
Microsoft Word
Microsoft Word のリモートでコードが実行される脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-40367 2026-05-21 10:52 2026-05-12 Show GitHub Exploit DB Packet Storm
432 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Office Long Term Servicing Channel (LTSC)
Microsoft Office クイック実行の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-40418 2026-05-21 10:52 2026-05-12 Show GitHub Exploit DB Packet Storm
433 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Office Long Term Servicing Channel (LTSC)
Microsoft Office クイック実行の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-40419 2026-05-21 10:52 2026-05-12 Show GitHub Exploit DB Packet Storm
434 8.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Office Long Term Servicing Channel (LTSC)
Microsoft Office クイック実行の特権の昇格の脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-40420 2026-05-21 10:52 2026-05-12 Show GitHub Exploit DB Packet Storm
435 5.8 警告
Network
traefik traefik traefikにおける送信データへの重要な情報の挿入に関する脆弱性 CWE-201
送信データへの重要な情報の挿入
CVE-2026-41181 2026-05-21 10:52 2026-05-15 Show GitHub Exploit DB Packet Storm
436 7.5 重要
Network
DHTMLX PDF Export Module DHTMLXのPDF Export Moduleにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41552 2026-05-21 10:52 2026-05-15 Show GitHub Exploit DB Packet Storm
437 9.1 緊急
Network
Apache Software Foundation Apache OFBiz Apache Software FoundationのApache OFBizにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-41919 2026-05-21 10:52 2026-05-19 Show GitHub Exploit DB Packet Storm
438 9.1 緊急
Network
LangGenius, Inc. Dify LangGenius, Inc.のDifyにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41947 2026-05-21 10:52 2026-05-18 Show GitHub Exploit DB Packet Storm
439 9.4 緊急
Network
LangGenius, Inc. Dify LangGenius, Inc.のDifyにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-41948 2026-05-21 10:52 2026-05-18 Show GitHub Exploit DB Packet Storm
440 7.5 重要
Network
LangGenius, Inc. Dify LangGenius, Inc.のDifyにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41949 2026-05-21 10:51 2026-05-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1281 4.1 MEDIUM
Network
- - When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Comp… New CWE-89
SQL Injection
CVE-2026-48136 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1282 5.3 MEDIUM
Network
- - A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. New CWE-122
Heap-based Buffer Overflow
CVE-2026-48135 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1283 7.5 HIGH
Network
- - When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-48133 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1284 8.1 HIGH
Network
- - The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, r… New CWE-122
Heap-based Buffer Overflow
CVE-2026-48131 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1285 7.1 HIGH
Network
- - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. Whil… New CWE-284
CWE-522
CWE-639
Improper Access Control
 Insufficiently Protected Credentials
 Authorization Bypass Through User-Controlled Key
CVE-2026-39968 2026-05-26 23:16 2026-05-23 Show GitHub Exploit DB Packet Storm
1286 7.5 HIGH
Network
- - An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attack… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2025-11482 2026-05-26 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1287 6.5 MEDIUM
Network
splunk ai_toolkit In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations… Update CWE-863
 Incorrect Authorization
CVE-2026-20238 2026-05-26 21:45 2026-05-21 Show GitHub Exploit DB Packet Storm
1288 3.8 LOW
Network
- - This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out ma… New CWE-1240
 Use of a Cryptographic Primitive with a Risky Implementation
CVE-2026-44410 2026-05-26 19:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1289 7.8 HIGH
Local
- - MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability New CWE-122
Heap-based Buffer Overflow
CVE-2026-25713 2026-05-26 19:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1290 7.8 HIGH
Local
- - MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability New CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2026-25104 2026-05-26 19:16 2026-05-26 Show GitHub Exploit DB Packet Storm