Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1661 7.8 重要
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-49014 2026-06-8 11:45 2026-05-27 Show GitHub Exploit DB Packet Storm
1662 8.8 重要
Network
Authentik Security Inc authentik Authentik Security Incのauthentikにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-49443 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1663 9.8 緊急
Network
Authentik Security Inc authentik Authentik Security Incのauthentikにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-49448 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1664 5.9 警告
Local
libexpat project libexpat libexpat projectのlibexpatにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-50219 2026-06-8 11:45 2026-06-4 Show GitHub Exploit DB Packet Storm
1665 5.3 警告
Network
morgan project morgan morgan projectのmorganにおける不適切なログ出力の無効化に関する脆弱性 CWE-117
不適切なログ出力の無効化
CVE-2026-5078 2026-06-8 11:45 2026-06-3 Show GitHub Exploit DB Packet Storm
1666 9.6 緊急
Network
huggingface transformers huggingfaceのtransformersにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-5241 2026-06-8 11:45 2026-06-3 Show GitHub Exploit DB Packet Storm
1667 8.1 重要
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7195 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1668 9.8 緊急
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-7198 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1669 8.8 重要
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-7201 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1670 5.4 警告
Network
appsmith appsmith appsmithにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-7299 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
41 9.1 CRITICAL
Network
openssl openssl Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various pot… Update CWE-354
 Improper Validation of Integrity Check Value
CVE-2026-34182 2026-06-16 03:13 2026-06-10 Show GitHub Exploit DB Packet Storm
42 7.5 HIGH
Network
openssl openssl Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unb… Update CWE-1325
 Improperly Controlled Sequential Memory Allocation
CVE-2026-34183 2026-06-16 03:12 2026-06-10 Show GitHub Exploit DB Packet Storm
43 5.0 MEDIUM
Network
openssl openssl Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verificatio… Update CWE-415
 Double Free
CVE-2026-35188 2026-06-16 03:12 2026-06-10 Show GitHub Exploit DB Packet Storm
44 5.7 MEDIUM
Adjacent
nuxt nuxt\/rspack-builder
nuxt\/webpack-builder
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete … Update CWE-749
 Exposed Dangerous Method or Function
CVE-2026-49993 2026-06-16 03:10 2026-06-12 Show GitHub Exploit DB Packet Storm
45 9.8 CRITICAL
Network
jmespath jmespath jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 ca… Update CWE-20
CWE-94
CWE-116
 Improper Input Validation 
Code Injection
 Improper Encoding or Escaping of Output
CVE-2026-54133 2026-06-16 03:09 2026-06-13 Show GitHub Exploit DB Packet Storm
46 5.4 MEDIUM
Network
nuxt nuxt Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redi… Update CWE-83
 Improper Neutralization of Script in Attributes in a Web Page
CVE-2026-45669 2026-06-16 03:09 2026-06-12 Show GitHub Exploit DB Packet Storm
47 5.3 MEDIUM
Network
nuxt nuxt
nuxt\/nitro-server
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0… Update CWE-284
CWE-288
Improper Access Control
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-47200 2026-06-16 03:09 2026-06-12 Show GitHub Exploit DB Packet Storm
48 5.4 MEDIUM
Network
nuxt nuxt
nuxt\/nitro-server
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.… Update CWE-79
CWE-349
CWE-444
Cross-site Scripting
 Acceptance of Extraneous Untrusted Data With Trusted Data
HTTP Request Smuggling
CVE-2026-46342 2026-06-16 03:09 2026-06-12 Show GitHub Exploit DB Packet Storm
49 5.4 MEDIUM
Network
nuxt nuxt\/rspack-builder
nuxt\/webpack-builder
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incompl… Update CWE-749
 Exposed Dangerous Method or Function
CVE-2026-45670 2026-06-16 03:08 2026-06-12 Show GitHub Exploit DB Packet Storm
50 9.8 CRITICAL
Network
apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadv… Update CWE-20
 Improper Input Validation 
CVE-2026-50628 2026-06-16 03:07 2026-06-12 Show GitHub Exploit DB Packet Storm