Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
951 6.1 警告
Network
th30d4y w4nn4d13/ip th30d4yのw4nn4d13/ipにおける複数の脆弱性 CWE-79
CWE-79
CWE-80
CVE-2026-41575 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
952 7.8 重要
Local
dail8859 Notepad Next dail8859のNotepad Nextにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-42214 2026-05-14 10:12 2026-05-7 Show GitHub Exploit DB Packet Storm
953 7.1 重要
Network
Legeling PromptHUB LegelingのPromptHUBにおける複数の脆弱性 CWE-20
CWE-693
CWE-918
CVE-2026-42261 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
954 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-862
CVE-2026-42809 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
955 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-116
CWE-20
CVE-2026-42810 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
956 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-917
CVE-2026-42811 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
957 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-284
CWE-732
CWE-863
CVE-2026-42812 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
958 7.5 重要
Network
Open JS Foundation fast-uri Open JS Foundationのfast-uriにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-6321 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
959 7.5 重要
Network
Open JS Foundation fast-uri Open JS Foundationのfast-uriにおける解釈の競合に関する脆弱性 CWE-436
解釈の競合
CVE-2026-6322 2026-05-14 10:12 2026-05-5 Show GitHub Exploit DB Packet Storm
960 4.8 警告
Network
KDDI Androidアプリ「あんしんフィルター for au」 Androidアプリ「あんしんフィルター for au」における重要情報の平文送信の脆弱性 CWE-Other
その他
CVE-2026-41281 2026-05-13 12:14 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1311 8.8 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th… CWE-89
CWE-841
SQL Injection
 Improper Enforcement of Behavioral Workflow
CVE-2026-43937 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1312 8.1 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43938 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1313 7.3 HIGH
Network
- - YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and… CWE-79
CWE-80
CWE-116
Cross-site Scripting
Basic XSS
 Improper Encoding or Escaping of Output
CVE-2026-43939 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1314 - - - DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw strin… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42300 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1315 6.5 MEDIUM
Network
- - requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addr… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42175 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1316 - - - Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affect… CWE-288
CWE-306
CWE-841
Authentication Bypass Using an Alternate Path or Channel
Missing Authentication for Critical Function
 Improper Enforcement of Behavioral Workflow
CVE-2026-42303 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1317 4.3 MEDIUM
Network
- - Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes… CWE-862
 Missing Authorization
CVE-2026-42541 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1318 8.8 HIGH
Network
- - AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed i… CWE-79
CWE-94
CWE-1188
Cross-site Scripting
Code Injection
 Insecure Default Initialization of Resource
CVE-2026-43892 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1319 8.2 HIGH
Network
- - ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address … CWE-184
CWE-918
 Incomplete Blacklist
Server-Side Request Forgery (SSRF) 
CVE-2026-43929 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm
1320 7.5 HIGH
Network
- - phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a by… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-44167 2026-05-14 03:24 2026-05-13 Show GitHub Exploit DB Packet Storm