Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5061 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27915 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5062 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27916 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5063 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows WFP NDIS ライトウェイト フィルター ドライバー (wfplwfs.sys) の特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27917 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5064 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows シェルの特権の昇格の脆弱性 CWE-362
競合状態
CVE-2026-27918 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5065 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-27919 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5066 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-27920 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5067 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows TDI 翻訳ドライバー (tdx.sys) の特権昇格の脆弱性 CWE-362
CWE-416
CVE-2026-27921 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5068 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27922 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5069 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
デスクトップ ウィンドウ マネージャーの特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27923 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
5070 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows 11 23h2
Microsoft Windows 10 22h2
Microsoft Windows 10 21h2
デスクトップ ウィンドウ マネージャーの特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27924 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 6.1 MEDIUM
Network
heartcombo devise Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.refer… Update CWE-601
Open Redirect
CVE-2026-40295 2026-05-30 03:55 2026-05-23 Show GitHub Exploit DB Packet Storm
2 5.5 MEDIUM
Local
bentoml bentoml BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symli… Update CWE-59
Link Following
CVE-2026-40610 2026-05-30 03:53 2026-05-23 Show GitHub Exploit DB Packet Storm
3 8.8 HIGH
Network
mintplexlabs anythingllm AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-con… New CWE-77
CWE-88
Command Injection
Argument Injection
CVE-2026-48116 2026-05-30 03:50 2026-05-29 Show GitHub Exploit DB Packet Storm
4 8.8 HIGH
Network
google chrome Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) New CWE-787
 Out-of-bounds Write
CVE-2026-9879 2026-05-30 03:46 2026-05-29 Show GitHub Exploit DB Packet Storm
5 4.3 MEDIUM
Network
google chrome Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical) New CWE-472
CWE-190
 External Control of Assumed-Immutable Web Parameter
 Integer Overflow or Wraparound
CVE-2026-9882 2026-05-30 03:44 2026-05-29 Show GitHub Exploit DB Packet Storm
6 8.8 HIGH
Network
google chrome Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) New CWE-416
 Use After Free
CVE-2026-9883 2026-05-30 03:43 2026-05-29 Show GitHub Exploit DB Packet Storm
7 8.8 HIGH
Network
google chrome Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) New CWE-416
 Use After Free
CVE-2026-9884 2026-05-30 03:41 2026-05-29 Show GitHub Exploit DB Packet Storm
8 7.8 HIGH
Local
google chrome Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical) New CWE-416
 Use After Free
CVE-2026-9887 2026-05-30 03:40 2026-05-29 Show GitHub Exploit DB Packet Storm
9 7.5 HIGH
Network
google chrome Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted … New CWE-416
 Use After Free
CVE-2026-9933 2026-05-30 03:27 2026-05-29 Show GitHub Exploit DB Packet Storm
10 4.3 MEDIUM
Network
google chrome Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) New CWE-457
 Use of Uninitialized Variable
CVE-2026-9935 2026-05-30 03:26 2026-05-29 Show GitHub Exploit DB Packet Storm