Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2201 8.1 重要
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-43913 2026-05-15 10:58 2026-05-11 Show GitHub Exploit DB Packet Storm
2202 9.8 緊急
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2026-43914 2026-05-15 10:58 2026-05-11 Show GitHub Exploit DB Packet Storm
2203 8.1 重要
Network
Pocket ID Pocket ID Pocket IDにおける複数の脆弱性 CWE-285
CWE-613
CVE-2026-43983 2026-05-15 10:58 2026-05-12 Show GitHub Exploit DB Packet Storm
2204 7.5 重要
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-44289 2026-05-15 10:58 2026-05-13 Show GitHub Exploit DB Packet Storm
2205 7.5 重要
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-44290 2026-05-15 10:58 2026-05-13 Show GitHub Exploit DB Packet Storm
2206 8.1 重要
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-44291 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
2207 5.3 警告
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-44292 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
2208 8.8 重要
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-44293 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
2209 5.3 警告
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-44294 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
2210 6.1 警告
Network
hono hono honoにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-44455 2026-05-15 10:57 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2541 5.4 MEDIUM
Network
- - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside… CWE-22
Path Traversal
CVE-2026-45571 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
2542 - - - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o… CWE-180
CWE-345
 Incorrect Behavior Order: Validate Before Canonicalize
 Insufficient Verification of Data Authenticity
CVE-2026-45022 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
2543 - - - Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. Howev… CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-9739 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
2544 5.3 MEDIUM
Network
- - opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-45292 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
2545 - - - A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign… CWE-494
 Download of Code Without Integrity Check
CVE-2026-9037 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
2546 - - - A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed… CWE-121
Stack-based Buffer Overflow
CVE-2026-9038 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
2547 - - - A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se… CWE-1188
 Insecure Default Initialization of Resource
CVE-2026-9039 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
2548 5.0 MEDIUM
Local
- - GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-read… CWE-116
 Improper Encoding or Escaping of Output
CVE-2026-44972 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
2549 - - - This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-32996 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
2550 - - - A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. CWE-36
 Absolute Path Traversal
CVE-2026-32997 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm