Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 4:05 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4641 8.8 重要
Network
OpenMage Magento OpenMageのMagentoにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2026-40488 2026-04-27 11:21 2026-04-20 Show GitHub Exploit DB Packet Storm
4642 9.1 緊急
Network
FreeScout FreeScout FreeScoutにおける複数の脆弱性 CWE-330
CWE-340
CVE-2026-40496 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
4643 8.1 重要
Network
FreeScout FreeScout FreeScoutにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40497 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4644 8.8 重要
Network
PJSIP pjsip PJSIPのpjsipにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40614 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4645 6.5 警告
Network
decidim decidim Decidim Free Software AssociationのDecidimにおける不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-40869 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4646 9.8 緊急
Network
PJSIP pjsip PJSIPのpjsipにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-40892 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4647 7.5 重要
Network
follow-redirects project Follow Redirects Follow Redirects projectのFollow Redirectsにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-40895 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4648 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-40907 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4649 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-40908 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4650 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40909 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
961 8.8 HIGH
Network
- - A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This vulnerability affects the function formSetPassword of the file /goform/formSetPassword. Executing a manipulation of the argument webpage can… New CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-10162 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
962 6.3 MEDIUM
Network
- - A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of t… New CWE-74
CWE-77
Injection
Command Injection
CVE-2026-10166 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
963 5.3 MEDIUM
Network
- - The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user … New CWE-862
 Missing Authorization
CVE-2026-8382 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
964 6.3 MEDIUM
Network
- - A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone ca… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10170 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
965 4.7 MEDIUM
Network
- - A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to … New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10171 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
966 6.3 MEDIUM
Network
- - A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php… New CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-10172 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
967 6.3 MEDIUM
Network
- - A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-comm… New CWE-693
 Protection Mechanism Failure
CVE-2026-10174 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
968 7.3 HIGH
Network
- - A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file appl… New CWE-287
Improper Authentication
CVE-2026-10167 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
969 6.3 MEDIUM
Network
- - A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file appl… New CWE-99
Resource Injection
CVE-2026-10168 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm
970 3.7 LOW
Network
- - A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_pa… New CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-10169 2026-06-2 00:15 2026-05-31 Show GitHub Exploit DB Packet Storm