Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3461 9.8 緊急
Network
Fleet Device Management fleet Fleet Device ManagementのfleetにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-26191 2026-05-20 13:21 2026-05-14 Show GitHub Exploit DB Packet Storm
3462 8.6 重要
Network
lfprojects mlflow lfprojectsのmlflowにおける根本の脆弱性による認証回避の脆弱性 CWE-305
根本の脆弱性による認証回避
CVE-2026-2652 2026-05-20 13:21 2026-05-15 Show GitHub Exploit DB Packet Storm
3463 9.1 緊急
Network
Timo Sirainen
Open-Xchange
Dovecot Pro
Dovecot
Timo Sirainen等の複数ベンダの製品における余分なパラメータの不適切な処理に関する脆弱性 CWE-235
余分なパラメータの不適切な処理
CVE-2026-27851 2026-05-20 13:21 2026-05-12 Show GitHub Exploit DB Packet Storm
3464 4.3 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-28759 2026-05-20 13:21 2026-05-18 Show GitHub Exploit DB Packet Storm
3465 5.5 警告
Local
マイクロソフト Microsoft Teams Microsoft Teams のなりすましの脆弱性 CWE-552
外部からアクセス可能なファイルまたはディレクトリ
CVE-2026-32185 2026-05-20 13:21 2026-05-12 Show GitHub Exploit DB Packet Storm
3466 7.2 重要
Network
Esri Portal for ArcGIS EsriのPortal for ArcGISにおける不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-33518 2026-05-20 13:21 2026-04-21 Show GitHub Exploit DB Packet Storm
3467 9.8 緊急
Network
Esri Portal for ArcGIS EsriのPortal for ArcGISにおける不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-33519 2026-05-20 13:20 2026-04-21 Show GitHub Exploit DB Packet Storm
3468 5.3 警告
Adjacent
Timo Sirainen
Open-Xchange
Dovecot Pro
Dovecot
Timo Sirainen等の複数ベンダの製品におけるリソースの挿入に関する脆弱性 CWE-99
リソースの挿入
CVE-2026-33603 2026-05-20 13:20 2026-05-12 Show GitHub Exploit DB Packet Storm
3469 6.1 警告
Network
シーメンス teamcenter シーメンスのteamcenterにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33862 2026-05-20 13:20 2026-05-12 Show GitHub Exploit DB Packet Storm
3470 7.5 重要
Network
シーメンス teamcenter シーメンスのteamcenterにおけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2026-33893 2026-05-20 13:20 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312061 - 2daybiz custom_t-shirt_design_script Cross-site scripting (XSS) vulnerability in 2daybiz Custom T-Shirt Design Script allows remote attackers to inject arbitrary web script or HTML via a review comment. CWE-79
Cross-site Scripting
CVE-2010-2692 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312062 - 2daybiz custom_t-shirt_design_script Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid par… CWE-89
SQL Injection
CVE-2010-2691 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312063 - jooforge com_gamesbox SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i… CWE-89
SQL Injection
CVE-2010-2690 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312064 - internetdm webdm_cms SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL commands via the cf_id parameter. CWE-89
SQL Injection
CVE-2010-2689 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312065 - site2nite boat_classifieds SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter. CWE-89
SQL Injection
CVE-2010-2688 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312066 - site2nite boat_classifieds SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter. CWE-89
SQL Injection
CVE-2010-2687 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312067 - topmanage olk_module Multiple SQL injection vulnerabilities in clientes.asp in the TopManage OLK module 1.91.30 for SAP allow remote attackers to execute arbitrary SQL commands via the (1) PriceFrom, (2) PriceTo, and (3)… CWE-89
SQL Injection
CVE-2010-2686 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312068 - customerparadigm pagedirector_cms siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-2685 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312069 - customerparadigm pagedirector_cms SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2010-2684 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm
312070 - customerparadigm pagedirector_cms SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter. CWE-89
SQL Injection
CVE-2010-2683 2024-11-21 10:17 2010-07-12 Show GitHub Exploit DB Packet Storm