Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4541 9.8 緊急
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41242 2026-04-24 11:41 2026-04-18 Show GitHub Exploit DB Packet Storm
4542 7.5 重要
Network
Junrar project Junrar Junrar projectのJunrarにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41245 2026-04-24 11:41 2026-04-20 Show GitHub Exploit DB Packet Storm
4543 7.5 重要
Network
projectdiscovery nuclei ProjectDiscovery, Inc.のNucleiにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41282 2026-04-24 11:41 2026-04-20 Show GitHub Exploit DB Packet Storm
4544 7.1 重要
Local
オートデスク株式会社 Autodesk Fusion オートデスク株式会社のAutodesk Fusionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4344 2026-04-24 11:41 2026-04-14 Show GitHub Exploit DB Packet Storm
4545 7.1 重要
Local
オートデスク株式会社 Autodesk Fusion オートデスク株式会社のAutodesk Fusionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4345 2026-04-24 11:41 2026-04-14 Show GitHub Exploit DB Packet Storm
4546 7.1 重要
Local
オートデスク株式会社 Autodesk Fusion オートデスク株式会社のAutodesk Fusionにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4369 2026-04-24 11:41 2026-04-14 Show GitHub Exploit DB Packet Storm
4547 5.5 警告
Local
GNU Project
レッドハット
GNU tar
Red Hat Hardened Images
Red Hat Enterprise Linux
GNU Project等の複数ベンダの製品における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2026-5704 2026-04-24 11:40 2026-04-6 Show GitHub Exploit DB Packet Storm
4548 6.4 警告
Network
Canonical Juju CanonicalのJujuにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-5774 2026-04-24 11:40 2026-04-10 Show GitHub Exploit DB Packet Storm
4549 7.8 重要
Local
CivetWeb project CivetWeb CivetWeb projectのCivetWebにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2026-5789 2026-04-24 11:40 2026-04-21 Show GitHub Exploit DB Packet Storm
4550 7.4 重要
Network
Eclipse Foundation Jetty Eclipse FoundationのJettyにおける複数の脆弱性 CWE-226
CWE-287
CVE-2026-5795 2026-04-24 11:40 2026-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
371 7.1 HIGH
Network
- - Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_s… New CWE-89
SQL Injection
CVE-2018-25380 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
372 8.2 HIGH
Network
- - Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attacke… New CWE-89
SQL Injection
CVE-2018-25379 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
373 6.2 MEDIUM
Local
- - Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can crea… New CWE-789
 Memory Allocation with Excessive Size Value
CVE-2018-25378 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
374 8.4 HIGH
Local
- - Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception ha… New CWE-120
Classic Buffer Overflow
CVE-2018-25377 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
375 8.4 HIGH
Local
- - Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling… New CWE-120
Classic Buffer Overflow
CVE-2018-25376 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
376 8.4 HIGH
Local
- - SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception ha… New CWE-121
Stack-based Buffer Overflow
CVE-2018-25375 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
377 7.5 HIGH
Network
- - Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers … New CWE-22
Path Traversal
CVE-2018-25374 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
378 8.4 HIGH
Local
- - SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting … New CWE-121
Stack-based Buffer Overflow
CVE-2018-25373 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
379 8.2 HIGH
Network
- - MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email param… New CWE-89
SQL Injection
CVE-2018-25372 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm
380 8.2 HIGH
Network
- - mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality… New CWE-89
SQL Injection
CVE-2018-25371 2026-05-26 00:16 2026-05-26 Show GitHub Exploit DB Packet Storm