Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4641 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-23396 2026-04-27 10:53 2026-03-26 Show GitHub Exploit DB Packet Storm
4642 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-23397 2026-04-27 10:53 2026-03-26 Show GitHub Exploit DB Packet Storm
4643 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-23398 2026-04-27 10:53 2026-03-26 Show GitHub Exploit DB Packet Storm
4644 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-23399 2026-04-27 10:53 2026-03-28 Show GitHub Exploit DB Packet Storm
4645 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-23400 2026-04-27 10:53 2026-03-29 Show GitHub Exploit DB Packet Storm
4646 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-23401 2026-04-27 10:53 2026-04-1 Show GitHub Exploit DB Packet Storm
4647 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-23402 2026-04-27 10:53 2026-04-1 Show GitHub Exploit DB Packet Storm
4648 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-23403 2026-04-27 10:53 2026-04-1 Show GitHub Exploit DB Packet Storm
4649 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-23404 2026-04-27 10:53 2026-04-1 Show GitHub Exploit DB Packet Storm
4650 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-23405 2026-04-27 10:53 2026-04-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
811 7.0 HIGH
Local
codesys development_system The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU r… Update CWE-276
Incorrect Default Permissions 
CVE-2026-44469 2026-05-29 05:09 2026-05-26 Show GitHub Exploit DB Packet Storm
812 7.8 HIGH
Local
mediaarea mediainfolib MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability Update CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2026-25104 2026-05-29 05:06 2026-05-26 Show GitHub Exploit DB Packet Storm
813 7.8 HIGH
Local
mediaarea mediainfolib MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability Update CWE-122
Heap-based Buffer Overflow
CVE-2026-25713 2026-05-29 05:03 2026-05-26 Show GitHub Exploit DB Packet Storm
814 7.5 HIGH
Network
joomla joomla\! Insufficient state checks lead to a vector that allows to bypass 2FA checks. Update CWE-287
NVD-CWE-noinfo
Improper Authentication
CVE-2026-48896 2026-05-29 04:46 2026-05-27 Show GitHub Exploit DB Packet Storm
815 7.5 HIGH
Network
joomla joomla\! Insufficient state checks lead to a vector that allows to bypass 2FA checks. Update CWE-287
Improper Authentication
CVE-2026-48897 2026-05-29 04:40 2026-05-27 Show GitHub Exploit DB Packet Storm
816 8.2 HIGH
Network
- - deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not b… New CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-46509 2026-05-29 04:16 2026-05-29 Show GitHub Exploit DB Packet Storm
817 7.5 HIGH
Network
joomla joomla\! An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. Update CWE-22
Path Traversal
CVE-2026-40384 2026-05-29 04:07 2026-05-27 Show GitHub Exploit DB Packet Storm
818 9.8 CRITICAL
Network
joomla joomla\! An improper access check allows unauthorized access to com_config webservice endpoints. Update CWE-284
NVD-CWE-noinfo
Improper Access Control
CVE-2026-35223 2026-05-29 04:07 2026-05-27 Show GitHub Exploit DB Packet Storm
819 7.8 HIGH
Local
- - Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in … New CWE-78
OS Command 
CVE-2026-45322 2026-05-29 03:56 2026-05-28 Show GitHub Exploit DB Packet Storm
820 8.8 HIGH
Network
- - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fie… New CWE-290
CWE-639
CWE-862
 Authentication Bypass by Spoofing
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
CVE-2026-46414 2026-05-29 03:56 2026-05-28 Show GitHub Exploit DB Packet Storm