Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1091 9.9 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46802 2026-06-22 11:54 2026-06-17 Show GitHub Exploit DB Packet Storm
1092 10 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-46803 2026-06-22 11:54 2026-06-17 Show GitHub Exploit DB Packet Storm
1093 8.7 重要
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおける権限管理に関する脆弱性 CWE-269
CWE-noinfo
CVE-2026-46804 2026-06-22 11:54 2026-06-17 Show GitHub Exploit DB Packet Storm
1094 9.3 緊急
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46805 2026-06-22 11:54 2026-06-17 Show GitHub Exploit DB Packet Storm
1095 8.2 重要
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-46806 2026-06-22 11:54 2026-06-17 Show GitHub Exploit DB Packet Storm
1096 9.8 緊急
Network
オラクル Oracle Identity Manager オラクルのOracle Identity Managerにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-46807 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
1097 8.7 重要
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46808 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
1098 9.1 緊急
Network
- オラクルのOracle WebCenter Sites Support Toolsにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46809 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
1099 6.5 警告
Network
オラクル Oracle Identity Manager オラクルのOracle Identity Managerにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46810 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
1100 6.1 警告
Network
オラクル Oracle Access Manager オラクルのOracle Access Managerにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46812 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
254251 9.1 CRITICAL
Network
squareup retrofit Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this t… CWE-611
XXE
CVE-2018-1000844 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254252 6.1 MEDIUM
Network
fatfreecrm fatfreecrm FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 t… CWE-79
Cross-site Scripting
CVE-2018-1000842 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254253 6.1 MEDIUM
Network
zend zendto Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the… CWE-79
Cross-site Scripting
CVE-2018-1000841 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254254 8.8 HIGH
Network
spotify luigi Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vulnerability in API e… CWE-352
 Origin Validation Error
CVE-2018-1000843 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254255 6.5 MEDIUM
Network
processing processing Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrat… CWE-611
XXE
CVE-2018-1000840 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254256 8.8 HIGH
Network
librehealth librehealth_ehr LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP fi… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-1000839 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254257 10.0 CRITICAL
Network
sleuthkit autopsy autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This… CWE-611
XXE
CVE-2018-1000838 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254258 10.0 CRITICAL
Network
obeo uml_designer UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. … CWE-611
XXE
CVE-2018-1000837 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254259 9.0 CRITICAL
Network
apereo bw-calendar-engine bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of … CWE-611
XXE
CVE-2018-1000836 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm
254260 10.0 CRITICAL
Network
keepassdx keepass_dx KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. CWE-611
XXE
CVE-2018-1000835 2024-11-21 12:40 2018-12-21 Show GitHub Exploit DB Packet Storm