Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1961 9.8 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-7301 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1962 9.1 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおけるパストラバーサルの脆弱性 CWE-35
パストラバーサル
CVE-2026-7302 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1963 9.8 緊急
Network
LMSYS Org SGLang LMSYS OrgのSGLangにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-7304 2026-05-21 10:50 2026-05-18 Show GitHub Exploit DB Packet Storm
1964 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CWE-125
CVE-2026-8212 2026-05-21 10:49 2026-05-9 Show GitHub Exploit DB Packet Storm
1965 5.5 警告
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおける複数の脆弱性 CWE-119
CWE-122
CWE-125
CVE-2026-8213 2026-05-21 10:49 2026-05-9 Show GitHub Exploit DB Packet Storm
1966 7.5 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける不変と仮定される Web パラメータの外部制御に関する脆弱性 CWE-472
不変と仮定される Web パラメータの外部制御
CVE-2026-8510 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
1967 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-8513 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
1968 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおけるライフタイムを通してのリソース制御に関する脆弱性 CWE-664
ライフタイムを通してのリソースの不適切な制御
CVE-2026-8517 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
1969 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける不変と仮定される Web パラメータの外部制御に関する脆弱性 CWE-472
不変と仮定される Web パラメータの外部制御
CVE-2026-8519 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
1970 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-8522 2026-05-21 10:49 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311241 - wordpress wordpress PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable. CWE-94
Code Injection
CVE-2003-1599 2024-11-21 08:47 2014-10-28 Show GitHub Exploit DB Packet Storm
311242 - wordpress wordpress SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable. CWE-89
SQL Injection
CVE-2003-1598 2024-11-21 08:47 2014-10-1 Show GitHub Exploit DB Packet Storm
311243 7.5 HIGH
Network
linux linux_kernel TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling. - CVE-2002-2438 2024-11-21 08:43 2021-05-18 Show GitHub Exploit DB Packet Storm
311244 9.8 CRITICAL
Network
snoopy_project snoopy Snoopy before 2.0.0 has a security hole in exec cURL CWE-20
 Improper Input Validation 
CVE-2002-2444 2024-11-21 08:43 2019-10-28 Show GitHub Exploit DB Packet Storm
311245 7.8 HIGH
Local
gnu gcc Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts. CWE-190
 Integer Overflow or Wraparound
CVE-2002-2439 2024-11-21 08:43 2019-10-24 Show GitHub Exploit DB Packet Storm
311246 - gehealthcare millennium_mg_firmware
millennium_nc_firmware
millennium_myosight_firmware
GE Healthcare Millennium MG, NC, and MyoSIGHT has a password of insite.genieacq for the insite account that cannot be changed without disabling product functionality for remote InSite support, which … CWE-255
Credentials Management
CVE-2002-2446 2024-11-21 08:43 2015-08-4 Show GitHub Exploit DB Packet Storm
311247 - gehealthcare millennium_myosight
millennium_nc
millennium_mg
GE Healthcare Millennium MG, NC, and MyoSIGHT has a default password of (1) root.genie for the root user, (2) "service." for the service user, (3) admin.genie for the admin user, (4) reboot for the r… NVD-CWE-noinfo
CVE-2002-2445 2024-11-21 08:43 2015-08-4 Show GitHub Exploit DB Packet Storm
311248 - mit
opensuse
fedoraproject
redhat
debian
canonical
kerberos_5
opensuse
fedora
enterprise_linux_server
enterprise_linux_workstation
enterprise_linux_server_aus
enterprise_linux_desktop
enterprise_linux_eus
debian_linux
ubunt…
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial o… CWE-20
 Improper Input Validation 
CVE-2002-2443 2024-11-21 08:43 2013-05-29 Show GitHub Exploit DB Packet Storm
311249 - mozilla firefox
thunderbird
seamonkey
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getC… CWE-264
Permissions, Privileges, and Access Controls
CVE-2002-2437 2024-11-21 08:43 2011-12-8 Show GitHub Exploit DB Packet Storm
311250 - mozilla firefox
thunderbird
seamonkey
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote… CWE-200
Information Exposure
CVE-2002-2436 2024-11-21 08:43 2011-12-8 Show GitHub Exploit DB Packet Storm