Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3321 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける関数の戻り値に対する不適切なチェックに関する脆弱性 CWE-253
関数の戻り値に対する不適切なチェック
CVE-2026-35340 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3322 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける安全でない一時ファイルに関する脆弱性 CWE-377
安全でない一時ファイル
CVE-2026-35342 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3323 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける常に不適切な制御フローの実装に関する脆弱性 CWE-670
常に不適切な制御フローの実装
CVE-2026-35343 2026-05-7 11:27 2026-04-22 Show GitHub Exploit DB Packet Storm
3324 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける未チェックの戻り値に関する脆弱性 CWE-252
未チェックの戻り値
CVE-2026-35344 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3325 5.3 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける複数の脆弱性 CWE-367
CWE-59
CVE-2026-35345 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3326 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける誤って解決された名前や参照の使用に関する脆弱性 CWE-706
誤って解決された名前や参照の使用
CVE-2026-35358 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3327 6.6 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-35365 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3328 4.4 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける例外的な状態のチェックに関する脆弱性 CWE-754
例外的な状態における不適切なチェック
CVE-2026-35366 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3329 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-35369 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3330 4.4 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-35370 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1221 8.2 HIGH
Network
- - Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query param… CWE-79
Cross-site Scripting
CVE-2026-45627 2026-05-30 03:17 2026-05-30 Show GitHub Exploit DB Packet Storm
1222 6.3 MEDIUM
Network
- - Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is … CWE-78
OS Command 
CVE-2026-45626 2026-05-30 03:17 2026-05-30 Show GitHub Exploit DB Packet Storm
1223 9.9 CRITICAL
Network
- - Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /a… CWE-862
 Missing Authorization
CVE-2026-45625 2026-05-30 03:17 2026-05-30 Show GitHub Exploit DB Packet Storm
1224 - - - Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it does NOT enforce organization scop… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-43917 2026-05-30 03:17 2026-05-30 Show GitHub Exploit DB Packet Storm
1225 8.1 HIGH
Network
- - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc… CWE-284
Improper Access Control
CVE-2026-35277 2026-05-30 03:17 2026-05-29 Show GitHub Exploit DB Packet Storm
1226 7.9 HIGH
Network
- - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network a… CWE-352
 Origin Validation Error
CVE-2026-35266 2026-05-30 03:17 2026-05-29 Show GitHub Exploit DB Packet Storm
1227 7.7 HIGH
Network
- - MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10107 2026-05-30 03:16 2026-05-30 Show GitHub Exploit DB Packet Storm
1228 4.7 MEDIUM
Network
- - A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results … CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-10070 2026-05-30 03:16 2026-05-30 Show GitHub Exploit DB Packet Storm
1229 7.3 HIGH
Network
- - A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side req… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10068 2026-05-30 03:16 2026-05-30 Show GitHub Exploit DB Packet Storm
1230 4.3 MEDIUM
Network
google chrome Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-10019 2026-05-30 03:16 2026-05-29 Show GitHub Exploit DB Packet Storm