Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1661 7.3 重要
Local
AIOHTTP AIOHTTP AIOHTTPにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-34993 2026-06-8 12:31 2026-06-2 Show GitHub Exploit DB Packet Storm
1662 3.1
Network
Django Software Foundation Django Django Software FoundationのDjangoにおける重要な情報を含むキャッシュの使用に関する脆弱性 CWE-524
重要な情報を含むキャッシュの使用
CVE-2026-35193 2026-06-8 12:31 2026-06-3 Show GitHub Exploit DB Packet Storm
1663 6.1 警告
Network
citeum opencti citeumのopenctiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-35212 2026-06-8 12:31 2026-06-2 Show GitHub Exploit DB Packet Storm
1664 8.2 重要
Network
Mosaic5G Flexric Mosaic5GのFlexricにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-37234 2026-06-8 12:31 2026-06-1 Show GitHub Exploit DB Packet Storm
1665 7.8 重要
Local
radare radare2 radareのradare2におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-40527 2026-06-8 12:31 2026-04-17 Show GitHub Exploit DB Packet Storm
1666 7.5 重要
Network
quic-go project quic-go quic-go projectのquic-goにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-40898 2026-06-8 12:31 2026-06-4 Show GitHub Exploit DB Packet Storm
1667 6.5 警告
Network
VMware Spring Cloud Function VMwareのSpring Cloud Functionにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-40989 2026-06-8 12:31 2026-06-1 Show GitHub Exploit DB Packet Storm
1668 6.5 警告
Network
VMware Spring Cloud Function VMwareのSpring Cloud Functionにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-40990 2026-06-8 12:31 2026-06-1 Show GitHub Exploit DB Packet Storm
1669 7.5 重要
Network
librechat librechat LibreChatにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-4276 2026-06-8 12:31 2026-03-16 Show GitHub Exploit DB Packet Storm
1670 4.8 警告
Network
ERLANG Erlang/OTP ERLANGのErlang/OTPにおける複数の脆弱性 CWE-295
CWE-296
CVE-2026-42789 2026-06-8 12:31 2026-05-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 19, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3811 2.5 LOW
Local
mintplexlabs anythingllm AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only … CWE-59
Link Following
CVE-2026-45403 2026-06-2 23:48 2026-05-29 Show GitHub Exploit DB Packet Storm
3812 - - - An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=t… CWE-287
Improper Authentication
CVE-2026-10611 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
3813 - - - Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during… - CVE-2026-10621 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
3814 - - - Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. - CVE-2026-10622 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
3815 7.5 HIGH
Network
- - Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to… CWE-22
Path Traversal
CVE-2026-49136 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3816 8.2 HIGH
Network
- - Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor… CWE-89
SQL Injection
CVE-2018-25433 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3817 6.5 MEDIUM
Adjacent
- - A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of… CWE-120
Classic Buffer Overflow
CVE-2026-3870 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3818 6.5 MEDIUM
Adjacent
- - A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial… CWE-120
Classic Buffer Overflow
CVE-2026-3871 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3819 - - - LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to th… CWE-280
Improper Handling of Insufficient Permissions or Privileges 
CVE-2026-10549 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3820 8.8 HIGH
Network
- - microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a cra… CWE-121
Stack-based Buffer Overflow
CVE-2026-43623 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm