Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
91 5.1 警告
Local
ImageMagick ImageMagick ImageMagickにおける複数の脆弱性 New CWE-125
CWE-129
CVE-2026-45624 2026-06-12 14:49 2026-06-10 Show GitHub Exploit DB Packet Storm
92 8.1 重要
Network
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows UPnP デバイス ホストのリモートでコードが実行される脆弱性 New CWE-416
CWE-843
CVE-2026-45635 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
93 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows NTFS のリモートでコードが実行される脆弱性 New CWE-122
CWE-20
CVE-2026-45636 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
94 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11 26h1
Microsoft …
Microsoft DWM Core ライブラリの特権の昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-45637 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
95 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-45638 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
96 7 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Microsoft Wind…
Windows Bluetooth ポート ドライバーの特権昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-45640 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
97 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Microsoft Wind…
Windows Hyper-V のリモートでコードが実行される脆弱性 New CWE-125
CWE-843
CVE-2026-45641 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
98 3.9
Physics
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Microsoft Azure 構成証明サービスとデバイス正常性構成証明サービスのなりすましの脆弱性 New CWE-20
不適切な入力確認
CVE-2026-45642 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
99 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows Server 2022
Windows Active Directory ドメイン サービス のリモートでコードが実行される脆弱性 New CWE-121
スタックオーバーフロー
CVE-2026-45648 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
100 7 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows カーネルの特権の昇格の脆弱性 New CWE-122
CWE-416
CVE-2026-45653 2026-06-12 14:49 2026-06-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2481 4.3 MEDIUM
Network
hcltech icontrol HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path… CWE-614
 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2025-52608 2026-06-5 03:38 2026-06-4 Show GitHub Exploit DB Packet Storm
2482 4.3 MEDIUM
Network
mozilla firefox JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. CWE-843
Type Confusion
CVE-2026-10702 2026-06-5 03:38 2026-06-3 Show GitHub Exploit DB Packet Storm
2483 5.3 MEDIUM
Network
openquantumsafe liboqs liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT … CWE-125
Out-of-bounds Read
CVE-2026-46344 2026-06-5 03:38 2026-05-30 Show GitHub Exploit DB Packet Storm
2484 5.3 MEDIUM
Network
openquantumsafe liboqs liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT … CWE-20
CWE-125
 Improper Input Validation 
Out-of-bounds Read
CVE-2026-44518 2026-06-5 03:36 2026-05-30 Show GitHub Exploit DB Packet Storm
2485 5.3 MEDIUM
Network
hcltech icontrol HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. CWE-693
 Protection Mechanism Failure
CVE-2025-52609 2026-06-5 03:34 2026-06-4 Show GitHub Exploit DB Packet Storm
2486 4.3 MEDIUM
Network
hcltech icontrol HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Spec… CWE-209
Information Exposure Through an Error Message
CVE-2025-52611 2026-06-5 03:34 2026-06-4 Show GitHub Exploit DB Packet Storm
2487 8.8 HIGH
Network
hcltech icontrol HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input param… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2025-52612 2026-06-5 03:32 2026-06-4 Show GitHub Exploit DB Packet Storm
2488 5.4 MEDIUM
Adjacent
macgregor interschalt_vdr_g4e_firmware Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2026-44611 2026-06-5 03:30 2026-05-30 Show GitHub Exploit DB Packet Storm
2489 5.4 MEDIUM
Adjacent
macgregor interschalt_vdr_g4e_firmware An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. CWE-522
 Insufficiently Protected Credentials
CVE-2026-42951 2026-06-5 03:30 2026-05-30 Show GitHub Exploit DB Packet Storm
2490 8.3 HIGH
Adjacent
macgregor interschalt_vdr_g4e_firmware The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. CWE-1392
 Use of Default Credentials
CVE-2026-42941 2026-06-5 03:27 2026-05-30 Show GitHub Exploit DB Packet Storm