Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201 6.5 警告
Network
PEVANS (Paul Evans ) Metrics::Any::Adapter::SignalFx PEVANS (Paul Evans )のMetrics::Any::Adapter::SignalFxにおける複数の脆弱性 New CWE-150
CWE-93
CVE-2026-50637
CVE-2026-50638
CVE-2026-50639
CVE-2026-9270
2026-06-26 11:51 2026-06-10 Show GitHub Exploit DB Packet Storm
202 7.5 重要
Network
Devolutions UniGetUI DevolutionsのUniGetUIにおける誤って解決された名前や参照の使用に関する脆弱性 New CWE-706
誤って解決された名前や参照の使用
CVE-2026-10696 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
203 7.8 重要
Local
デル AIOps Collector デルのAIOps Collectorにおけるデフォルトの認証情報の使用に関する脆弱性 New CWE-1392
デフォルトの認証情報の使用
CVE-2026-32652 2026-06-26 11:50 2026-06-17 Show GitHub Exploit DB Packet Storm
204 9.1 緊急
Network
UI UniFi OS Server UIのUniFi OS Serverにおける入力確認に関する脆弱性 New CWE-20
不適切な入力確認
CVE-2026-33000 2026-06-26 11:50 2026-05-22 Show GitHub Exploit DB Packet Storm
205 7.7 重要
Network
UI UniFi Dream Machine Special Edition Firmware (UDM-SE)
UniFi Cloud Gateway Ultra Firmware (UCG-Ultra)
UniFi Network Video Re…
UIのEnterprise Fortress Gateway Firmware (EFG)等の複数製品におけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-34911 2026-06-26 11:50 2026-05-22 Show GitHub Exploit DB Packet Storm
206 8.8 重要
Adjacent
Palo Alto Networks IDIRA Privilege Cloud Connector Palo Alto NetworksのIDIRA Privilege Cloud Connectorにおける証明書検証に関する脆弱性 New CWE-295
不正な証明書検証
CVE-2026-45170 2026-06-26 11:50 2026-06-12 Show GitHub Exploit DB Packet Storm
207 8.8 重要
Network
Palo Alto Networks IDIRA Privileged Session Manager (PSM) Palo Alto NetworksのIDIRA Privileged Session Manager (PSM)におけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-45171 2026-06-26 11:50 2026-06-11 Show GitHub Exploit DB Packet Storm
208 8.8 重要
Network
Palo Alto Networks Privileged Session Manager (PSM) Palo Alto NetworksのPrivileged Session Manager (PSM)におけるOS コマンドインジェクションの脆弱性 New CWE-78
OSコマンド・インジェクション
CVE-2026-45172 2026-06-26 11:50 2026-06-11 Show GitHub Exploit DB Packet Storm
209 8.2 重要
Local
マイクロソフト Microsoft MANA Network Driver Microsoft Azure ネットワーク アダプターの特権昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-45476 2026-06-26 11:50 2026-06-9 Show GitHub Exploit DB Packet Storm
210 7.8 重要
Local
Leejet Stable-diffusion.cpp LeejetのStable-diffusion.cppにおける複数の脆弱性 New CWE-122
CWE-787
CVE-2026-47747 2026-06-26 11:50 2026-06-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
254291 7.5 HIGH
Network
lightsaml lightsaml LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2018-1000165 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254292 7.5 HIGH
Network
gunicorn
debian
gunicorn
debian_linux
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an atta… CWE-93
CRLF Injection
CVE-2018-1000164 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254293 6.1 MEDIUM
Network
projectfloodlight floodlight Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploit… CWE-79
Cross-site Scripting
CVE-2018-1000163 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254294 6.1 MEDIUM
Network
parsedown parsedown Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be ex… CWE-79
Cross-site Scripting
CVE-2018-1000162 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254295 5.7 MEDIUM
Network
nmap nmap nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is runn… CWE-22
Path Traversal
CVE-2018-1000161 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254296 6.1 MEDIUM
Network
risingstack protect RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in lib/rules/xss.js that can result in dangerous XSS strings being validated as s… CWE-79
Cross-site Scripting
CVE-2018-1000160 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254297 8.8 HIGH
Network
cmsmadesimple cms_made_simple cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2018-1000158 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254298 7.8 HIGH
Local
oisf suricata-update OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 … CWE-502
 Deserialization of Untrusted Data
CVE-2018-1000167 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254299 5.9 MEDIUM
Network
tlslite-ng_project tlslite-ng tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper Validation of Integrity Check Value vulnerability in TLS implementation, tlsli… CWE-354
 Improper Validation of Integrity Check Value
CVE-2018-1000159 2024-11-21 12:39 2018-04-19 Show GitHub Exploit DB Packet Storm
254300 5.4 MEDIUM
Network
jenkins jenkins A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Creat… CWE-79
Cross-site Scripting
CVE-2018-1000170 2024-11-21 12:39 2018-04-16 Show GitHub Exploit DB Packet Storm