Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 22, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
321 9.8 緊急
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35286 2026-06-22 11:40 2026-06-17 Show GitHub Exploit DB Packet Storm
322 6.6 警告
Network
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおける権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-35291 2026-06-22 11:40 2026-06-17 Show GitHub Exploit DB Packet Storm
323 10 緊急
Network
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35292 2026-06-22 11:40 2026-06-17 Show GitHub Exploit DB Packet Storm
324 9.8 緊急
Network
- オラクルのOracle WebCenter Sites Support Toolsにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35293 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
325 9.9 緊急
Network
オラクル Oracle Identity Manager オラクルのOracle Identity Managerにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-35294 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
326 7.5 重要
Network
- オラクルのOracle WebCenter Sites Support Toolsにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35295 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
327 9.8 緊急
Network
- オラクルのOracle WebCenter Sites Support Toolsにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35296 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
328 9.1 緊急
Network
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-35298 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
329 8.8 重要
Network
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-35299 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
330 9.8 緊急
Network
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおける信頼できないデータのデシリアライゼーションに関する脆弱性 New CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-35300 2026-06-22 11:39 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
256251 5.5 MEDIUM
Local
partclone_project partclone partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial o… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6596 2024-11-21 12:30 2017-03-10 Show GitHub Exploit DB Packet Storm
256252 6.1 MEDIUM
Network
mantisbt mantisbt A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' par… CWE-79
Cross-site Scripting
CVE-2017-6797 2024-11-21 12:30 2017-03-10 Show GitHub Exploit DB Packet Storm
256253 6.1 MEDIUM
Network
django-epiceditor_project django-epiceditor There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field. CWE-79
Cross-site Scripting
CVE-2017-6591 2024-11-21 12:30 2017-03-10 Show GitHub Exploit DB Packet Storm
256254 6.3 MEDIUM
Physics
canonical ubuntu_linux An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login s… CWE-863
 Incorrect Authorization
CVE-2017-6590 2024-11-21 12:30 2017-03-10 Show GitHub Exploit DB Packet Storm
256255 6.1 MEDIUM
Network
epiceditor_project epiceditor EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document. CWE-79
Cross-site Scripting
CVE-2017-6589 2024-11-21 12:30 2017-03-10 Show GitHub Exploit DB Packet Storm
256256 7.2 HIGH
Network
mail-masta_project mail-masta A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscri… CWE-89
SQL Injection
CVE-2017-6578 2024-11-21 12:30 2017-03-9 Show GitHub Exploit DB Packet Storm
256257 7.2 HIGH
Network
mail-masta_project mail-masta A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id. CWE-89
SQL Injection
CVE-2017-6577 2024-11-21 12:30 2017-03-9 Show GitHub Exploit DB Packet Storm
256258 7.2 HIGH
Network
mail-masta_project mail-masta A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter:… CWE-89
SQL Injection
CVE-2017-6576 2024-11-21 12:30 2017-03-9 Show GitHub Exploit DB Packet Storm
256259 7.2 HIGH
Network
mail-masta_project mail-masta A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member… CWE-89
SQL Injection
CVE-2017-6575 2024-11-21 12:30 2017-03-9 Show GitHub Exploit DB Packet Storm
256260 7.2 HIGH
Network
mail-masta_project mail-masta A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter… CWE-89
SQL Injection
CVE-2017-6574 2024-11-21 12:30 2017-03-9 Show GitHub Exploit DB Packet Storm