Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
21 9.8 緊急
Network
Defense Unicorns UDS Identity Config Defense UnicornsのUDS Identity Configにおける複数の脆弱性 New CWE-287
CWE-303
CVE-2026-46389 2026-06-16 13:40 2026-06-5 Show GitHub Exploit DB Packet Storm
22 5.8 警告
Local
Shane Pearman (spearman) unbounded-spsc Shane Pearman (spearman)のunbounded-spscにおける複数の脆弱性 New CWE-125
CWE-415
CWE-704
CWE-787
CVE-2026-46690 2026-06-16 13:40 2026-06-12 Show GitHub Exploit DB Packet Storm
23 5.3 警告
Network
nuxt nuxt
nuxt/nitro-server
Nuxtのnuxt/nitro-server等の複数製品における複数の脆弱性 New CWE-284
CWE-288
CVE-2026-47200 2026-06-16 13:40 2026-06-12 Show GitHub Exploit DB Packet Storm
24 5.4 警告
Network
マイクロソフト Microsoft Exchange Server
Microsoft Exchange Server Subscription Edition (SE)
Microsoft Exchange Server のなりすましの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-47631 2026-06-16 13:40 2026-06-9 Show GitHub Exploit DB Packet Storm
25 8.2 重要
Network
ERLANG Erlang Runtime System (ERTS)
Erlang/OTP
ERLANGのErlang/OTP等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 New CWE-121
スタックオーバーフロー
CVE-2026-49759 2026-06-16 13:40 2026-06-10 Show GitHub Exploit DB Packet Storm
26 5.5 警告
Local
ERLANG Erl Interface
Erlang/OTP
ERLANGのErl Interface等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 New CWE-121
スタックオーバーフロー
CVE-2026-49760 2026-06-16 13:40 2026-06-10 Show GitHub Exploit DB Packet Storm
27 5.7 警告
Adjacent
nuxt nuxt/webpack-builder
nuxt/rspack-builder
Nuxtのnuxt/rspack-builder等の複数製品における危険なメソッドや機能の公開に関する脆弱性 New CWE-749
危険なメソッドや機能の公開
CVE-2026-49993 2026-06-16 13:39 2026-06-12 Show GitHub Exploit DB Packet Storm
28 9.8 緊急
Network
jmespath project jmespath JMESPathにおける複数の脆弱性 New CWE-116
CWE-20
CWE-94
CVE-2026-54133 2026-06-16 13:39 2026-06-12 Show GitHub Exploit DB Packet Storm
29 5.5 警告
Local
- アップルのmacOSにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2025-24165 2026-06-16 13:39 2026-06-11 Show GitHub Exploit DB Packet Storm
30 5.5 警告
Local
- アップルのmacOSにおけるUNIX Symbolic Link のフォローに関する脆弱性 New CWE-61
UNIX Symbolic Link のフォロー
CVE-2025-43278 2026-06-16 13:39 2026-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319851 9.8 CRITICAL
Network
angeljudesuarez tailoring_management_system A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of … CWE-89
SQL Injection
CVE-2024-8611 2024-09-19 02:24 2024-09-10 Show GitHub Exploit DB Packet Storm
319852 7.8 HIGH
Local
ivanti workspace_control DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges. CWE-426
 Untrusted Search Path
CVE-2024-44103 2024-09-19 02:18 2024-09-11 Show GitHub Exploit DB Packet Storm
319853 6.1 MEDIUM
Network
teleogistic invite_anyone Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a… CWE-79
Cross-site Scripting
CVE-2024-43327 2024-09-19 02:07 2024-08-18 Show GitHub Exploit DB Packet Storm
319854 4.8 MEDIUM
Network
starkdigital wp_testimonial_widget Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Wi… CWE-79
Cross-site Scripting
CVE-2024-43967 2024-09-19 02:00 2024-08-27 Show GitHub Exploit DB Packet Storm
319855 8.8 HIGH
Network
thimpress learnpress Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2. CWE-352
 Origin Validation Error
CVE-2024-39641 2024-09-19 01:57 2024-08-27 Show GitHub Exploit DB Packet Storm
319856 8.8 HIGH
Network
themeum tutor_lms Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. CWE-352
 Origin Validation Error
CVE-2024-39645 2024-09-19 01:46 2024-08-27 Show GitHub Exploit DB Packet Storm
319857 8.8 HIGH
Network
sender sender Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Autom… CWE-352
 Origin Validation Error
CVE-2024-39657 2024-09-19 01:25 2024-08-27 Show GitHub Exploit DB Packet Storm
319858 8.8 HIGH
Network
10up simple_local_avatars Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10. CWE-352
 Origin Validation Error
CVE-2024-43116 2024-09-19 01:22 2024-08-27 Show GitHub Exploit DB Packet Storm
319859 8.8 HIGH
Network
loftware spectrum Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. CWE-611
XXE
CVE-2023-37233 2024-09-19 01:10 2024-09-11 Show GitHub Exploit DB Packet Storm
319860 9.8 CRITICAL
Network
loftware spectrum Loftware Spectrum through 4.6 has unprotected JMX Registry. NVD-CWE-noinfo
CVE-2023-37234 2024-09-19 01:05 2024-09-11 Show GitHub Exploit DB Packet Storm