Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2871 5.5 警告
Local
WebAssembly Binaryen WebAssemblyのBinaryenにおける到達可能なアサーションに関する脆弱性 CWE-617
到達可能なアサーション
CVE-2026-8257 2026-05-25 10:19 2026-05-11 Show GitHub Exploit DB Packet Storm
2872 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-8486 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
2873 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2026-8487 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
2874 7.5 重要
Network
Progress Software Corporation MOVEit Automation Web Admin Progress Software CorporationのMOVEit Automation Web Adminにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-8488 2026-05-25 10:19 2026-05-20 Show GitHub Exploit DB Packet Storm
2875 4.3 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-8563 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
2876 4.2 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-8564 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
2877 4.7 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-8565 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
2878 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-8569 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
2879 4.3 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける過度に許容されるクロスドメインホワイトリストに関する脆弱性 CWE-942
過度に許容されるクロスドメインホワイトリスト
CVE-2026-8576 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
2880 3.1
Network
Google Google Chrome GoogleのGoogle Chromeにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-8578 2026-05-25 10:18 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318751 6.1 MEDIUM
Network
projectcaruso flaming_forms The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators. CWE-79
Cross-site Scripting
CVE-2024-7691 2024-10-5 02:15 2024-09-2 Show GitHub Exploit DB Packet Storm
318752 7.5 HIGH
Network
oceanicsoft valeapp Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).This issue affects ValeApp: … CWE-312
 Cleartext Storage of Sensitive Information
CVE-2024-8644 2024-10-5 02:14 2024-09-27 Show GitHub Exploit DB Packet Storm
318753 9.8 CRITICAL
Network
oceanicsoft valeapp Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0. CWE-384
 Session Fixation
CVE-2024-8643 2024-10-5 02:14 2024-09-27 Show GitHub Exploit DB Packet Storm
318754 6.1 MEDIUM
Network
projectcaruso flaming_forms The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used agains… CWE-79
Cross-site Scripting
CVE-2024-7692 2024-10-5 02:14 2024-09-2 Show GitHub Exploit DB Packet Storm
318755 7.5 HIGH
Network
oceanicsoft valeapp Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information.This issue affects ValeApp: before v2.0.0. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-8609 2024-10-5 02:12 2024-09-27 Show GitHub Exploit DB Packet Storm
318756 9.8 CRITICAL
Network
oceanicsoft valeapp Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0. CWE-89
SQL Injection
CVE-2024-8607 2024-10-5 02:12 2024-09-27 Show GitHub Exploit DB Packet Storm
318757 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: the warning dereferencing obj for nbio_v7_4 if ras_manager obj null, don't print NBIO err data CWE-476
 NULL Pointer Dereference
CVE-2024-46819 2024-10-5 02:11 2024-09-27 Show GitHub Exploit DB Packet Storm
318758 5.4 MEDIUM
Network
oceanicsoft valeapp Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS.This issue affects ValeApp: before v2.0.0. CWE-79
Cross-site Scripting
CVE-2024-8608 2024-10-5 02:11 2024-09-27 Show GitHub Exploit DB Packet Storm
318759 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix negative array index read Avoid using the negative values for clk_idex as an index into an array pptable->DpmDesc… CWE-129
 Improper Validation of Array Index
CVE-2024-46821 2024-10-5 02:06 2024-09-27 Show GitHub Exploit DB Packet Storm
318760 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: Check for unset descriptor Make sure the descriptor has been set before looking at maxpacket. This fixes a nul… CWE-476
 NULL Pointer Dereference
CVE-2024-44960 2024-10-5 01:44 2024-09-5 Show GitHub Exploit DB Packet Storm