Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5081 8.1 重要
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-28741 2026-04-24 11:31 2026-04-15 Show GitHub Exploit DB Packet Storm
5082 8.8 重要
Network
infiniflow ragflow infiniflowのragflowにおける複数の脆弱性 CWE-1336
CWE-20
CWE-78
CWE-94
CVE-2026-28797 2026-04-24 11:31 2026-04-3 Show GitHub Exploit DB Packet Storm
5083 7.1 重要
Network
Daylight Studio FUEL CMS Daylight StudioのFUEL CMSにおけるパスワード管理機能に関する脆弱性 CWE-640
パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み
CVE-2026-30459 2026-04-24 11:31 2026-04-16 Show GitHub Exploit DB Packet Storm
5084 9.8 緊急
Network
TOTOLINK a3300r ファームウェア TOTOLINKのa3300r ファームウェアにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-31170 2026-04-24 11:31 2026-04-9 Show GitHub Exploit DB Packet Storm
5085 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows Simple Search Discovery Protocol (SSDP) サービスの特権昇格の脆弱性 CWE-362
競合状態
CVE-2026-32068 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
5086 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows Projected File System の特権の昇格の脆弱性 CWE-415
二重解放
CVE-2026-32069 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
5087 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows 共通ログ ファイル システム ドライバーの特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32070 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
5088 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows ローカル セキュリティ機関サブシステム サービス (LSASS) のサービス拒否の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-32071 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
5089 6.2 警告
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Active Directory のなりすましの脆弱性 CWE-287
不適切な認証
CVE-2026-32072 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
5090 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32073 2026-04-24 11:31 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 8.2 HIGH
Network
- - MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter.… New CWE-89
SQL Injection
CVE-2018-25411 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
72 7.1 HIGH
Network
- - SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send G… New CWE-89
SQL Injection
CVE-2018-25410 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
73 8.8 HIGH
Network
- - SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload … New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-25409 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
74 7.5 HIGH
Network
- - The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename pa… New CWE-22
Path Traversal
CVE-2018-25408 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
75 8.2 HIGH
Network
- - eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A… New CWE-89
SQL Injection
CVE-2018-25407 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
76 8.2 HIGH
Network
- - eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A… New CWE-89
SQL Injection
CVE-2018-25406 2026-05-31 01:17 2026-05-31 Show GitHub Exploit DB Packet Storm
77 8.2 HIGH
Network
- - eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A… New CWE-89
SQL Injection
CVE-2018-25405 2026-05-31 01:16 2026-05-31 Show GitHub Exploit DB Packet Storm
78 8.8 HIGH
Network
- - A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewal… New CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-10120 2026-05-31 00:16 2026-05-31 Show GitHub Exploit DB Packet Storm
79 4.3 MEDIUM
Network
- - A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media… Update CWE-476
 NULL Pointer Dereference
CVE-2025-70116 2026-05-31 00:16 2026-05-28 Show GitHub Exploit DB Packet Storm
80 8.8 HIGH
Network
- - A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name… New CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-10119 2026-05-30 23:16 2026-05-30 Show GitHub Exploit DB Packet Storm