Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 4:05 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3361 5.4 警告
Network
Wolters Kluwer Financial Services, Inc. LEX Baza Dokumentow Wolters Kluwer Financial Services, Inc.のLEX Baza Dokumentowにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-1493 2026-05-7 11:30 2026-04-30 Show GitHub Exploit DB Packet Storm
3362 5.7 警告
Adjacent
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-20020 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
3363 6.1 警告
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-80
クロスサイトスクリプティング (Basic XSS)
CVE-2026-20070 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
3364 5.8 警告
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品におけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-20073 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
3365 7.7 重要
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-20100 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
3366 8.6 重要
Network
NVIDIA NemoClaw NVIDIAのNemoClawにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-24222 2026-05-7 11:30 2026-04-28 Show GitHub Exploit DB Packet Storm
3367 6.3 警告
Local
NVIDIA NemoClaw NVIDIAのNemoClawにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-24231 2026-05-7 11:30 2026-04-28 Show GitHub Exploit DB Packet Storm
3368 6.5 警告
Network
SAP Manage Reference Structures SAPのManage Reference Structuresにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-27679 2026-05-7 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
3369 7.5 重要
Network
Mercurycom MIPC252W Firmware MercurycomのMIPC252W FirmwareにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-31256 2026-05-7 11:30 2026-04-27 Show GitHub Exploit DB Packet Storm
3370 4.9 警告
Network
Anviz Global Anviz CX7 Firmware Anviz GlobalのAnviz CX7 Firmwareにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-31927 2026-05-7 11:30 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1191 9.8 CRITICAL
Network
deltaww diaview There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project. CWE-321
 Use of Hard-coded Cryptographic Key
CVE-2026-9642 2026-05-30 04:53 2026-05-27 Show GitHub Exploit DB Packet Storm
1192 7.5 HIGH
Network
microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. CWE-502
 Deserialization of Untrusted Data
CVE-2026-41104 2026-05-30 04:46 2026-05-23 Show GitHub Exploit DB Packet Storm
1193 5.5 MEDIUM
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP me… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-48735 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1194 3.3 LOW
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams w… CWE-834
 Excessive Iteration
CVE-2026-48156 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1195 5.5 MEDIUM
Local
pypdf_project pypdf pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in l… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-48155 2026-05-30 04:38 2026-05-29 Show GitHub Exploit DB Packet Storm
1196 9.8 CRITICAL
Network
ibm engineering_lifecycle_management IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap… CWE-863
 Incorrect Authorization
CVE-2026-3660 2026-05-30 04:31 2026-05-27 Show GitHub Exploit DB Packet Storm
1197 9.6 CRITICAL
Network
amirraminfar dozzle Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepti… CWE-346
 Origin Validation Error
CVE-2026-44985 2026-05-30 04:30 2026-05-27 Show GitHub Exploit DB Packet Storm
1198 7.1 HIGH
Adjacent
free5gc free5gc free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it… CWE-358
 Improperly Implemented Security Check for Standard
CVE-2026-42081 2026-05-30 04:24 2026-05-28 Show GitHub Exploit DB Packet Storm
1199 8.6 HIGH
Network
amirraminfar dozzle Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is re… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45298 2026-05-30 04:23 2026-05-27 Show GitHub Exploit DB Packet Storm
1200 7.5 HIGH
Network
tanium server Tanium addressed a denial of service vulnerability in Tanium Server. CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2026-9156 2026-05-30 04:16 2026-05-27 Show GitHub Exploit DB Packet Storm