Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
132371 9.8 緊急
Network
YITHEMES YITH WOOCOMMERCE GIFT CARDS WordPress 用 YITH WooCommerce Gift Cards Premium プラグインにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2021-3120 2021-11-11 17:53 2021-01-28 Show GitHub Exploit DB Packet Storm
132372 9.8 緊急
Network
Inspur ClusterEngine Inspur ClusterEngine における引数の挿入または変更に関する脆弱性 CWE-88
引数の挿入または変更
CVE-2020-21224 2021-11-11 17:53 2020-08-13 Show GitHub Exploit DB Packet Storm
132373 7.8 重要
Local
アドバンテック株式会社 WebAccess/SCADA Advantech WebAccess/SCADA における不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2020-13554 2021-11-11 17:23 2020-10-20 Show GitHub Exploit DB Packet Storm
132374 6.1 警告
Network
NanoHTTPD NanoHTTPD NanoHTTPD におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2020-13697 2021-11-11 17:13 2020-05-29 Show GitHub Exploit DB Packet Storm
132375 4.3 警告
Network
Google Rendertron Rendertron におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2020-8902 2021-11-11 17:13 2020-07-3 Show GitHub Exploit DB Packet Storm
132376 7.3 重要
Network
レッドハット Louketo Proxy keycloak における根本の脆弱性による認証回避の脆弱性 CWE-305
根本の脆弱性による認証回避
CVE-2020-14359 2021-11-11 17:13 2020-08-13 Show GitHub Exploit DB Packet Storm
132377 9.8 緊急
Network
geojson2kml geojson2kml geojson2kml における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2020-28429 2021-11-11 17:13 2020-12-11 Show GitHub Exploit DB Packet Storm
132378 7.5 重要
Network
KACO new energy XP100U ファームウェア KACO New Energy XP100U における認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2021-3252 2021-11-11 17:13 2021-01-18 Show GitHub Exploit DB Packet Storm
132379 8.2 重要
Local
レッドハット
Fedora Project
GNU Project
grub2
Fedora
Red Hat Enterprise Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
grub2 における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2020-25632 2021-11-11 17:00 2020-09-16 Show GitHub Exploit DB Packet Storm
132380 7.6 重要
Physics
GNU Project
Fedora Project
レッドハット
Fedora
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
grub2
Red Hat Enterprise Linux
grub2 における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2020-25647 2021-11-11 16:51 2020-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
441 6.1 MEDIUM
Network
umbraco umbraco_cms Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor t… Update CWE-601
Open Redirect
CVE-2026-46616 2026-06-13 04:34 2026-06-11 Show GitHub Exploit DB Packet Storm
442 8.8 HIGH
Network
apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template inj… Update CWE-94
Code Injection
CVE-2026-50223 2026-06-13 04:30 2026-06-11 Show GitHub Exploit DB Packet Storm
443 7.8 HIGH
Local
microsoft pc_manager Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. Update CWE-284
Improper Access Control
CVE-2026-49161 2026-06-13 04:30 2026-06-10 Show GitHub Exploit DB Packet Storm
444 9.8 CRITICAL
Network
vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Exec… Update CWE-502
 Deserialization of Untrusted Data
CVE-2026-41699 2026-06-13 04:28 2026-06-11 Show GitHub Exploit DB Packet Storm
445 8.1 HIGH
Network
microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. Update CWE-74
Injection
CVE-2026-42835 2026-06-13 04:28 2026-06-10 Show GitHub Exploit DB Packet Storm
446 8.2 HIGH
Local
adobe acrobat_dc
acrobat_reader_dc
acrobat
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the cu… Update CWE-427
 Uncontrolled Search Path Element
CVE-2026-47937 2026-06-13 04:23 2026-06-10 Show GitHub Exploit DB Packet Storm
447 5.5 MEDIUM
Local
adobe acrobat_dc
acrobat_reader_dc
acrobat
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v… Update CWE-125
Out-of-bounds Read
CVE-2026-47926 2026-06-13 04:23 2026-06-10 Show GitHub Exploit DB Packet Storm
448 5.5 MEDIUM
Local
adobe acrobat_dc
acrobat_reader_dc
acrobat
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could… Update CWE-190
 Integer Overflow or Wraparound
CVE-2026-47925 2026-06-13 04:23 2026-06-10 Show GitHub Exploit DB Packet Storm
449 5.5 MEDIUM
Local
adobe acrobat_dc
acrobat_reader_dc
acrobat
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulner… Update CWE-416
 Use After Free
CVE-2026-47924 2026-06-13 04:23 2026-06-10 Show GitHub Exploit DB Packet Storm
450 7.8 HIGH
Local
microsoft powertoys Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. Update CWE-285
Improper Authorization
CVE-2026-42902 2026-06-13 04:23 2026-06-10 Show GitHub Exploit DB Packet Storm