Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2691 5.3 警告
Network
forms project forms NextcloudのFormsにおける外部からアクセス可能なファイルまたはディレクトリに関する脆弱性 CWE-552
外部からアクセス可能なファイルまたはディレクトリ
CVE-2026-45543 2026-06-8 11:48 2026-06-1 Show GitHub Exploit DB Packet Storm
2692 8.1 重要
Network
Get-hermes Hermes Web UI Get-hermesのHermes Web UIにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-6832 2026-06-8 11:48 2026-04-21 Show GitHub Exploit DB Packet Storm
2693 8.8 重要
Network
radare Radare2 MCP Server radareのRadare2 MCP ServerにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-6942 2026-06-8 11:48 2026-04-23 Show GitHub Exploit DB Packet Storm
2694 7.3 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2026-8876 2026-06-8 11:48 2026-06-3 Show GitHub Exploit DB Packet Storm
2695 7.5 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおける暗号強度に関する脆弱性 CWE-326
不適切な暗号強度
CVE-2026-8878 2026-06-8 11:48 2026-06-3 Show GitHub Exploit DB Packet Storm
2696 7.5 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-8879 2026-06-8 11:48 2026-06-3 Show GitHub Exploit DB Packet Storm
2697 7.8 重要
Local
Amazon.com, Inc. Kiro CLI Amazon.com, Inc.のKiro CLIにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-9255 2026-06-8 11:48 2026-05-22 Show GitHub Exploit DB Packet Storm
2698 9.9 緊急
Network
Flowintel Flowintel Flowintelにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-9813 2026-06-8 11:48 2026-05-28 Show GitHub Exploit DB Packet Storm
2699 7.8 重要
Local
huggingface transformers huggingfaceのtransformersにおける複数の脆弱性 CWE-1066
CWE-502
CVE-2026-4372 2026-06-8 11:48 2026-05-24 Show GitHub Exploit DB Packet Storm
2700 6.1 警告
Network
Avatar Uploader project Avatar Uploader Avatar Uploader projectのAvatar Uploaderにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2022-50957 2026-06-8 11:48 2026-05-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 25, 2026, 4:04 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311071 - ibm omnifind esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3895 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311072 - ibm omnifind Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Ent… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3894 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311073 - ibm omnifind The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbit… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3893 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311074 - ibm omnifind Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID… NVD-CWE-Other
CVE-2010-3892 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311075 - ibm omnifind Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authenticatio… CWE-352
 Origin Validation Error
CVE-2010-3891 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311076 - ibm omnifind Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration i… CWE-79
Cross-site Scripting
CVE-2010-3890 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311077 - php
canonical
php
ubuntu_linux
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass … CWE-20
 Improper Input Validation 
CVE-2010-3870 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311078 - microsoft forefront_unified_access_gateway Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web… CWE-79
Cross-site Scripting
CVE-2010-3936 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311079 - adobe flash_media_server Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vuln… CWE-94
Code Injection
CVE-2010-3635 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311080 - adobe flash_media_server Unspecified vulnerability in the edge process in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service via unknow… NVD-CWE-noinfo
CVE-2010-3634 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm