Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2681 6.5 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-4527 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
2682 4.3 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-6063 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
2683 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-6073 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
2684 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-6335 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
2685 4.3 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-6883 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
2686 9.8 緊急
Network
libexpat project libexpat libexpat projectのlibexpatにおけるエントロピー不足に関する脆弱性 CWE-331
エントロピー不足
CVE-2026-7210 2026-05-18 11:24 2026-05-11 Show GitHub Exploit DB Packet Storm
2687 8.8 重要
Adjacent
ZyXEL WRE6505 ファームウェア ZyXELのWRE6505 ファームウェアにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-7256 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
2688 4.4 警告
Local
ZyXEL WRE6505 ファームウェア ZyXELのWRE6505 ファームウェアにおける重要な情報のセキュアでない格納に関する脆弱性 CWE-922
重要な情報のセキュアでない格納
CVE-2026-7257 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
2689 7.5 重要
Network
ZyXEL NWA1100-N ファームウェア ZyXELのNWA1100-N ファームウェアにおける古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-7287 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
2690 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-7377 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312011 - - - A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. T… CWE-611
XXE
CVE-2020-26066 2024-11-20 06:57 2024-11-19 Show GitHub Exploit DB Packet Storm
312012 - - - Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access. - CVE-2024-45422 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312013 - - - Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access. - CVE-2024-45420 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312014 - - - Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access. - CVE-2024-45419 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312015 4.3 MEDIUM
Network
- - IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2024-37070 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312016 - - - Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) - CVE-2024-11395 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312017 - - - A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine… - CVE-2024-51503 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312018 - - - This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerab… - CVE-2024-21697 2024-11-20 06:56 2024-11-20 Show GitHub Exploit DB Packet Storm
312019 5.4 MEDIUM
Network
oretnom23 online_eyewear_shop A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2024-11247 2024-11-20 06:55 2024-11-16 Show GitHub Exploit DB Packet Storm
312020 8.2 HIGH
Network
ibm engineering_lifecycle_optimization_-_engineering_insights IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit … CWE-611
XXE
CVE-2024-39726 2024-11-20 06:51 2024-11-16 Show GitHub Exploit DB Packet Storm