Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1271 7.2 重要
Network
MariaDB Corporation Ab. MariaDB MariaDB Corporation Ab.のMariaDBにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-48165 2026-06-17 15:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1272 7.8 重要
Local
レッドハット
X.Org Foundation
X.Org X Server
Red Hat Enterprise Linux
xwayland
レッドハット等の複数ベンダの製品における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-50264 2026-06-17 15:39 2026-06-5 Show GitHub Exploit DB Packet Storm
1273 7.5 重要
Network
Express.js Multer Express.jsのMulterにおける不完全なクリーンアップに関する脆弱性 CWE-459
不完全なクリーンアップ
CVE-2026-5038 2026-06-17 15:39 2026-06-15 Show GitHub Exploit DB Packet Storm
1274 7.5 重要
Network
Express.js Multer Express.jsのMulterにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-5079 2026-06-17 15:39 2026-06-15 Show GitHub Exploit DB Packet Storm
1275 8.1 重要
Network
Zoom Video Communications, Inc. Zoom Meeting SDK
Zoom Workplace
Zoom Video Communications, Inc.のZoom Meeting SDK等の複数製品におけるカスタム URL スキームのハンドラの不適切な認可に関する脆弱性 CWE-939
カスタム URL スキームのハンドラの不適切な認可
CVE-2026-53408 2026-06-17 15:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1276 6.6 警告
Local
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-53820 2026-06-17 15:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1277 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-53821 2026-06-17 15:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1278 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける複数の脆弱性 CWE-367
CWE-77
CVE-2026-53822 2026-06-17 15:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1279 8.1 重要
Network
OpenClaw OpenClaw OpenClawにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-53823 2026-06-17 15:38 2026-06-12 Show GitHub Exploit DB Packet Storm
1280 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-53824 2026-06-17 15:38 2026-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1001 4.3 MEDIUM
Network
- - Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to t… CWE-256
Plaintext Storage of a Password 
CVE-2026-57302 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1002 4.2 MEDIUM
Network
- - A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified… CWE-352
 Origin Validation Error
CVE-2026-57306 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1003 4.2 MEDIUM
Network
- - A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-spe… CWE-862
 Missing Authorization
CVE-2026-57307 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1004 6.2 MEDIUM
Network
- - A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can lead to a denial of service. An attacker can imperson… CWE-121
Stack-based Buffer Overflow
CVE-2026-12488 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1005 10.0 CRITICAL
Network
- - GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP me… CWE-121
Stack-based Buffer Overflow
CVE-2026-12485 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1006 9.1 CRITICAL
Network
- - Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker… CWE-78
OS Command 
CVE-2026-12486 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1007 10.0 CRITICAL
Network
- - GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP me… CWE-121
Stack-based Buffer Overflow
CVE-2026-12846 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1008 10.0 CRITICAL
Network
- - GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP me… CWE-121
Stack-based Buffer Overflow
CVE-2026-12847 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1009 10.0 CRITICAL
Network
- - GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP me… CWE-121
Stack-based Buffer Overflow
CVE-2026-12848 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1010 9.1 CRITICAL
Network
- - Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker… CWE-78
OS Command 
CVE-2026-12849 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm