Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2061 6.5 警告
Network
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows TCP/IP ドライバーのセキュリティ機能のバイパスの脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-35422 2026-05-18 12:16 2026-05-12 Show GitHub Exploit DB Packet Storm
2062 5.4 警告
Network
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows 11 Telnet クライアントの情報漏えいの脆弱性 CWE-125
境界外読み取り
CVE-2026-35423 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2063 7.5 重要
Network
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
インターネット キー交換 (IKE) プロトコルのサービス拒否の脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-35424 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2064 5.4 警告
Network
Frappe Frappe Frappeにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-3837 2026-05-18 12:15 2026-04-22 Show GitHub Exploit DB Packet Storm
2065 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Windows カーネルの特権の昇格の脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-40369 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2066 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Microsoft Cryptographic Services の特権の昇格の脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40377 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2067 6.2 警告
Physics
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2016
Microsoft Windows 10 1809
Microsoft Windows 11 23h2
Microsoft Wind…
Windows ボリューム マネージャー拡張ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-125
CWE-197
CVE-2026-40380 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2068 7.5 重要
Network
PHPOffice PhpSpreadsheet PHPOfficeのPhpSpreadsheetにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-40902 2026-05-18 12:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2069 6.8 警告
Adjacent
VMware Spring Boot VMwareのSpring Bootにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40970 2026-05-18 12:15 2026-04-27 Show GitHub Exploit DB Packet Storm
2070 9.1 緊急
Network
VMware Spring Boot VMwareのSpring Bootにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40971 2026-05-18 12:15 2026-04-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2631 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… CWE-77
Command Injection
CVE-2026-38702 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
2632 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier… CWE-77
Command Injection
CVE-2026-38703 2026-05-29 23:09 2026-05-29 Show GitHub Exploit DB Packet Storm
2633 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ve… CWE-77
Command Injection
CVE-2026-38707 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
2634 9.8 CRITICAL
Network
inhandnetworks ir315_firmware
ir302_firmware
ir615_firmware
ir305_firmware
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlie… CWE-77
Command Injection
CVE-2026-38704 2026-05-29 23:08 2026-05-29 Show GitHub Exploit DB Packet Storm
2635 8.6 HIGH
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st… CWE-193
 Off-by-one Error
CVE-2026-49127 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2636 5.3 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF by… CWE-93
CRLF Injection
CVE-2026-49130 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2637 5.8 MEDIUM
Network
- - Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allow… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-49129 2026-05-29 23:07 2026-05-29 Show GitHub Exploit DB Packet Storm
2638 4.1 MEDIUM
Network
- - A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endp… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10052 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
2639 2.7 LOW
Network
- - A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL que… CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-10078 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm
2640 7.7 HIGH
Network
- - A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice tha… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42965 2026-05-29 23:06 2026-05-29 Show GitHub Exploit DB Packet Storm