Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
791 4.4 警告
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows フィルタリング プラットフォーム (WFP) のセキュリティ機能のバイパスの脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-32209 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
792 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows Event Logging Service の特権の昇格の脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-33834 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
793 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Wind…
Windows Cloud Files Mini Filter ドライバーの特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33835 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
794 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows TCP/IP Local の特権昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-33837 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
795 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows メッセージ キュー (MSMQ) の特権昇格の脆弱性 CWE-415
二重解放
CVE-2026-33838 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
796 7 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Wind…
Win32k の特権の昇格の脆弱性 CWE-362
競合状態
CVE-2026-33839 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
797 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Win32k の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-33840 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
798 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows 11 24h2
Microsoft Wind…
Windows カーネルの特権の昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-33841 2026-05-18 12:17 2026-05-12 Show GitHub Exploit DB Packet Storm
799 7.5 重要
Network
MediaWiki MediaWiki MediaWikiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-34087 2026-05-18 12:17 2026-05-11 Show GitHub Exploit DB Packet Storm
800 7.5 重要
Network
MediaWiki MediaWiki MediaWikiにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-34088 2026-05-18 12:17 2026-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1671 - - - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated SQL injection issue in the frontend user order hist… CWE-89
SQL Injection
CVE-2026-45800 2026-05-19 02:28 2026-05-16 Show GitHub Exploit DB Packet Storm
1672 7.5 HIGH
Network
- - Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX … CWE-22
Path Traversal
CVE-2018-25325 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1673 5.3 MEDIUM
Network
- - Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM… CWE-352
 Origin Validation Error
CVE-2018-25327 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1674 8.2 HIGH
Network
- - Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. At… CWE-89
SQL Injection
CVE-2018-25330 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1675 5.3 MEDIUM
Network
- - Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HT… CWE-352
 Origin Validation Error
CVE-2018-25336 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1676 4.3 MEDIUM
Network
- - Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo… CWE-352
 Origin Validation Error
CVE-2018-25337 2026-05-19 02:28 2026-05-17 Show GitHub Exploit DB Packet Storm
1677 7.5 HIGH
Network
siemens teamcenter A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All … CWE-798
 Use of Hard-coded Credentials
CVE-2026-33893 2026-05-19 02:26 2026-05-12 Show GitHub Exploit DB Packet Storm
1678 5.4 MEDIUM
Network
- - Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is proce… CWE-79
Cross-site Scripting
CVE-2026-23695 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1679 4.3 MEDIUM
Network
- - CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG file… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2021-47958 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1680 8.8 HIGH
Network
- - Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager… CWE-94
Code Injection
CVE-2021-47964 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm