Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223791 6.8 警告 IBM - IBM Flex System Manager におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-5424 2013-10-29 16:37 2013-10-22 Show GitHub Exploit DB Packet Storm
223792 7.5 危険 Igor Sysoev - nginx のデフォルト設定における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0337 2013-10-29 15:52 2013-10-6 Show GitHub Exploit DB Packet Storm
223793 6.8 警告 ARM Ltd. (旧 Offspark) - PolarSSL の ssl_tls.c の ssl_read_record 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-5914 2013-10-29 15:47 2013-10-1 Show GitHub Exploit DB Packet Storm
223794 4.3 警告 Dwayne C. Litzenberger - PyCrypto の Crypto.Random.atfork 関数における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-1445 2013-10-29 15:29 2013-10-14 Show GitHub Exploit DB Packet Storm
223795 7.5 危険 VideoLAN - VideoLAN VLC media player におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-6283 2013-10-29 15:23 2013-10-25 Show GitHub Exploit DB Packet Storm
223796 4.9 警告 Canonical - Apport における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1067 2013-10-29 15:19 2013-10-24 Show GitHub Exploit DB Packet Storm
223797 5.8 警告 WellinTech - WellinTech KingView の KChartXY.ocx における任意のファイルを生成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6128 2013-10-29 11:39 2013-10-22 Show GitHub Exploit DB Packet Storm
223798 5.8 警告 WellinTech - WellinTech KingView の SuperGrid.ocx における任意のファイルを生成される脆弱性 CWE-22
パス・トラバーサル
CVE-2013-6127 2013-10-29 11:34 2013-10-22 Show GitHub Exploit DB Packet Storm
223799 5 警告 Puppet - Puppet Enterprise におけるアクセス制限を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-4965 2013-10-29 11:22 2013-10-15 Show GitHub Exploit DB Packet Storm
223800 6.8 警告 Puppet - Puppet Enterprise のダッシュボードレポートにおける任意の YAML コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-4957 2013-10-29 11:16 2013-10-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 4.3 MEDIUM
Network
jenkins job_import Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of cred… Update CWE-269
 Improper Privilege Management
CVE-2026-48926 2026-06-2 23:49 2026-05-28 Show GitHub Exploit DB Packet Storm
202 8.8 HIGH
Network
- - CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.… New CWE-20
 Improper Input Validation 
CVE-2026-7195 2026-06-2 23:48 2026-06-2 Show GitHub Exploit DB Packet Storm
203 2.5 LOW
Local
mintplexlabs anythingllm AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only … Update CWE-59
Link Following
CVE-2026-45403 2026-06-2 23:48 2026-05-29 Show GitHub Exploit DB Packet Storm
204 8.6 HIGH
Network
- - An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in open… New CWE-369
 Divide By Zero
CVE-2026-37232 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
205 - - - An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=t… New CWE-287
Improper Authentication
CVE-2026-10611 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
206 - - - A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST… New - CVE-2026-35717 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
207 - - - Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during… New - CVE-2026-10621 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
208 - - - Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. New - CVE-2026-10622 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
209 7.5 HIGH
Network
- - Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to… New CWE-22
Path Traversal
CVE-2026-49136 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
210 8.2 HIGH
Network
- - Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor… New CWE-89
SQL Injection
CVE-2018-25433 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm