Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247131 4.3 警告 asp ziyaretci defteri - ASP Ziyaretci Defteri の mesaj_formu.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3887 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
247132 4.3 警告 ASP indir - husrevforum の philboard_search.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3885 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
247133 7.5 危険 ASP indir - husrevforum の philboard_forum.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-3884 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
247134 5.1 警告 datadynamics - Data Dynamics ActiveBar ActiveX コントロールにおけるファイルを作成される脆弱性 - CVE-2007-3883 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
247135 4.3 警告 CA Technologies - CA Anti-Virus などの arclib.dll におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3875 2012-06-26 15:54 2007-07-25 Show GitHub Exploit DB Packet Storm
247136 7.8 危険 altiris - Symantec Altiris Deployment Solution の tftp/mftp デーモンにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-3874 2012-06-26 15:54 2007-11-6 Show GitHub Exploit DB Packet Storm
247137 5 警告 deutsche post - Stampit Web におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2007-3871 2012-06-26 15:54 2007-09-12 Show GitHub Exploit DB Packet Storm
247138 4.3 警告 8e6 Technologies - 8e6 R3000 Enterprise Filter におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3842 2012-06-26 15:54 2007-07-17 Show GitHub Exploit DB Packet Storm
247139 2.6 注意 exlibris group - Ex Libris MetaLib におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3835 2012-06-26 15:54 2007-07-17 Show GitHub Exploit DB Packet Storm
247140 4.3 警告 exlibris group - Ex Libris ALEPH におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3834 2012-06-26 15:54 2007-07-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
481 7.9 HIGH
Network
oracle rest_data_services Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network a… Update CWE-400
CWE-352
 Uncontrolled Resource Consumption
 Origin Validation Error
CVE-2026-35266 2026-06-4 03:03 2026-05-29 Show GitHub Exploit DB Packet Storm
482 7.5 HIGH
Network
hkuds deepcode DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying… Update CWE-22
Path Traversal
CVE-2026-32847 2026-06-4 03:02 2026-05-29 Show GitHub Exploit DB Packet Storm
483 9.1 CRITICAL
Network
electerm_project electerm electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid… Update CWE-326
CWE-329
CWE-353
CWE-759
CWE-916
Inadequate Encryption Strength
 Not Using a Random IV with CBC Mode
 Missing Support for Integrity Check
 Use of a One-Way Hash without a Salt
 Use of Password Hash With Insufficient Computational Effort
CVE-2026-45787 2026-06-4 02:56 2026-05-29 Show GitHub Exploit DB Packet Storm
484 7.8 HIGH
Local
electerm_project electerm electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0. Update CWE-94
CWE-732
CWE-940
Code Injection
 Incorrect Permission Assignment for Critical Resource
 Improper Verification of Source of a Communication Channel
CVE-2026-45353 2026-06-4 02:54 2026-05-29 Show GitHub Exploit DB Packet Storm
485 8.8 HIGH
Network
oracle e-business_suite Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all… Update CWE-306
Missing Authentication for Critical Function
CVE-2026-46826 2026-06-4 02:43 2026-05-29 Show GitHub Exploit DB Packet Storm
486 8.8 HIGH
Network
oracle e-business_suite Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability al… Update CWE-269
CWE-284
CWE-287
CWE-306
 Improper Privilege Management
Improper Access Control
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-46827 2026-06-4 02:43 2026-05-29 Show GitHub Exploit DB Packet Storm
487 8.1 HIGH
Network
oracle e-business_suite Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all… Update CWE-284
Improper Access Control
CVE-2026-46828 2026-06-4 02:42 2026-05-29 Show GitHub Exploit DB Packet Storm
488 7.5 HIGH
Network
oracle rest_data_services Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-46829 2026-06-4 02:41 2026-05-29 Show GitHub Exploit DB Packet Storm
489 6.5 MEDIUM
Network
nextcloud approval Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to f… New CWE-285
Improper Authorization
CVE-2026-45275 2026-06-4 02:39 2026-06-2 Show GitHub Exploit DB Packet Storm
490 9.1 CRITICAL
Network
oracle e-business_suite Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploi… Update CWE-284
Improper Access Control
CVE-2026-46819 2026-06-4 02:37 2026-05-29 Show GitHub Exploit DB Packet Storm