Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211 5.5 警告
Local
Advanced Micro Devices (AMD) uprof Advanced Micro Devices (AMD)のuprofにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 New CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-0466 2026-06-17 15:35 2026-06-9 Show GitHub Exploit DB Packet Storm
212 10 緊急
Network
MISP MISP MISPにおける認証に関する脆弱性 New CWE-287
CWE-noinfo
CVE-2026-10611 2026-06-17 15:35 2026-06-2 Show GitHub Exploit DB Packet Storm
213 6.3 警告
Local
Zephyr Project Zephyr Zephyr ProjectのZephyrにおける解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-10635 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
214 9.8 緊急
Network
Altium Altium On-Prem Enterprise Server AltiumのAltium On-Prem Enterprise Serverにおける複数の脆弱性 New CWE-22
CWE-798
CVE-2026-11414 2026-06-17 15:35 2026-06-5 Show GitHub Exploit DB Packet Storm
215 8.8 重要
Network
Altium Altium On-Prem Enterprise Server AltiumのAltium On-Prem Enterprise Serverにおける複数の脆弱性 New CWE-22
CWE-434
CVE-2026-11419 2026-06-17 15:35 2026-06-5 Show GitHub Exploit DB Packet Storm
216 9.8 緊急
Network
Altium Altium On-Prem Enterprise Server AltiumのAltium On-Prem Enterprise Serverにおける複数の脆弱性 New CWE-22
CWE-306
CVE-2026-11420 2026-06-17 15:35 2026-06-5 Show GitHub Exploit DB Packet Storm
217 8.8 重要
Network
Devolutions Devolutions Remote Desktop Manager DevolutionsのDevolutions Remote Desktop ManagerにおけるOS コマンドインジェクションの脆弱性 New CWE-78
OSコマンド・インジェクション
CVE-2026-12161 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
218 5.5 警告
Network
Devolutions Devolutions Remote Desktop Manager DevolutionsのDevolutions Remote Desktop Managerにおけるホストの不一致による証明書の検証に関する脆弱性 New CWE-297
ホストの不一致による証明書の不適切な検証
CVE-2026-12162 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
219 8.8 重要
Network
D-Link Corporation DCS-935L ファームウェア D-Link CorporationのDCS-935L ファームウェアにおける複数の脆弱性 New CWE-119
CWE-134
CVE-2026-12174 2026-06-17 15:35 2026-06-13 Show GitHub Exploit DB Packet Storm
220 8.8 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-12289 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
255171 5.9 MEDIUM
Network
mozilla firefox A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed… CWE-20
 Improper Input Validation 
CVE-2017-7770 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255172 9.8 CRITICAL
Network
debian
redhat
mozilla
debian_linux
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_server_aus
enterprise_linux_server_eus
firefox
firefox_esr
thunderb…
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of the… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-7779 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255173 5.5 MEDIUM
Local
mozilla firefox
firefox_esr
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided b… CWE-200
Information Exposure
CVE-2017-7768 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255174 5.5 MEDIUM
Local
mozilla firefox
firefox_esr
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privile… CWE-269
 Improper Privilege Management
CVE-2017-7767 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255175 7.8 HIGH
Local
mozilla firefox
firefox_esr
An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and… NVD-CWE-noinfo
CVE-2017-7766 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255176 7.5 HIGH
Network
mozilla firefox
firefox_esr
thunderbird
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows display… CWE-20
 Improper Input Validation 
CVE-2017-7765 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255177 5.3 MEDIUM
Network
mozilla
debian
firefox
thunderbird
firefox_esr
debian_linux
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for do… CWE-20
 Improper Input Validation 
CVE-2017-7764 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255178 5.3 MEDIUM
Network
mozilla
debian
firefox
firefox_esr
thunderbird
debian_linux
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS… CWE-20
 Improper Input Validation 
CVE-2017-7763 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255179 7.5 HIGH
Network
redhat
mozilla
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
firefox
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerabilit… CWE-20
 Improper Input Validation 
CVE-2017-7762 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm
255180 7.5 HIGH
Network
mozilla
google
firefox
android
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin polic… CWE-200
Information Exposure
CVE-2017-7759 2024-11-21 12:32 2018-06-12 Show GitHub Exploit DB Packet Storm