Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2361 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける無限ループに関する脆弱性 CWE-835
無限ループ
CVE-2025-71267 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2362 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2025-71268 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2363 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71269 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2364 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71270 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2365 6.5 警告
Network
Splunk splunk cloud platform
Splunk
SplunkのSplunk等の複数製品におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-20239 2026-05-25 10:24 2026-05-20 Show GitHub Exploit DB Packet Storm
2366 6.5 警告
Network
Splunk splunk cloud platform
Splunk
SplunkのSplunk等の複数製品における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-20240 2026-05-25 10:24 2026-05-20 Show GitHub Exploit DB Packet Storm
2367 6.1 警告
Local
Eaton easySoft EatonのeasySoftにおける復元可能な形式でのパスワード保存に関する脆弱性 CWE-257
復元可能な形式でのパスワード保存
CVE-2026-22614 2026-05-25 10:24 2026-03-10 Show GitHub Exploit DB Packet Storm
2368 7.5 重要
Network
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-23242 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2369 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-23243 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
2370 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-23244 2026-05-25 10:24 2026-03-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311591 5.5 MEDIUM
Local
clusterlabs cluster_glue
pacemaker
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its o… CWE-287
Improper Authentication
CVE-2010-2496 2024-11-21 10:16 2021-10-18 Show GitHub Exploit DB Packet Storm
311592 7.8 HIGH
Local
linux linux_kernel A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file … - CVE-2010-2525 2024-11-21 10:16 2021-06-22 Show GitHub Exploit DB Packet Storm
311593 7.5 HIGH
Network
znc znc NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections. CWE-476
 NULL Pointer Dereference
CVE-2010-2488 2024-11-21 10:16 2019-11-13 Show GitHub Exploit DB Packet Storm
311594 9.8 CRITICAL
Network
syscp_project syscp syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot. CWE-20
 Improper Input Validation 
CVE-2010-2476 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311595 7.5 HIGH
Network
shibboleth
debian
service_provider
debian_linux
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default… CWE-200
CWE-916
Information Exposure
 Use of Password Hash With Insufficient Computational Effort
CVE-2010-2450 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311596 6.5 MEDIUM
Network
gource gource Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack. CWE-20
 Improper Input Validation 
CVE-2010-2449 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311597 9.8 CRITICAL
Network
gitolite gitolite gitolite before 1.4.1 does not filter src/ or hooks/ from path names. CWE-20
 Improper Input Validation 
CVE-2010-2447 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311598 6.5 MEDIUM
Network
drupal drupal Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal s… CWE-20
 Improper Input Validation 
CVE-2010-2473 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311599 4.8 MEDIUM
Network
drupal drupal Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which c… CWE-79
Cross-site Scripting
CVE-2010-2472 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm
311600 6.1 MEDIUM
Network
drupal drupal Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. CWE-79
Cross-site Scripting
CVE-2010-2250 2024-11-21 10:16 2019-11-8 Show GitHub Exploit DB Packet Storm