Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3631 5.5 警告
Local
Pengutronix e.K. barebox Pengutronix e.K.のbareboxにおける無限ループに関する脆弱性 CWE-835
無限ループ
CVE-2026-34962 2026-05-15 11:02 2026-05-11 Show GitHub Exploit DB Packet Storm
3632 7.8 重要
Local
Pengutronix e.K. barebox Pengutronix e.K.のbareboxにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-34963 2026-05-15 11:02 2026-05-11 Show GitHub Exploit DB Packet Storm
3633 8.8 重要
Network
マイクロソフト Microsoft SharePoint Server Microsoft SharePoint Server のリモートでコードが実行される脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-35439 2026-05-15 11:02 2026-05-12 Show GitHub Exploit DB Packet Storm
3634 5.9 警告
Network
IBM IBM WebSphere Application Server IBMのIBM WebSphere Application Serverにおける権限管理に関する脆弱性 CWE-269
CWE-noinfo
CVE-2026-3621 2026-05-15 11:02 2026-04-23 Show GitHub Exploit DB Packet Storm
3635 5.9 警告
Local
The Go Project Go The Go ProjectのGoにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-39817 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
3636 5.3 警告
Local
The Go Project Go The Go ProjectのGoにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-39819 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
3637 7.5 重要
Network
The Go Project Go The Go ProjectのGoにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-39820 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
3638 6.1 警告
Network
The Go Project Go The Go ProjectのGoにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-39823 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
3639 5.3 警告
Network
The Go Project Go The Go ProjectのGoにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-39825 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
3640 6.1 警告
Network
The Go Project Go The Go ProjectのGoにおけるエンコードおよびエスケープに関する脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2026-39826 2026-05-15 11:01 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2251 8.8 HIGH
Network
7-zip 7-zip 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCu… CWE-190
CWE-787
 Integer Overflow or Wraparound
 Out-of-bounds Write
CVE-2026-48095 2026-06-8 22:40 2026-06-6 Show GitHub Exploit DB Packet Storm
2252 4.3 MEDIUM
Network
google chrome Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium securi… CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-11031 2026-06-8 22:40 2026-06-5 Show GitHub Exploit DB Packet Storm
2253 6.5 MEDIUM
Network
google chrome Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medi… CWE-346
 Origin Validation Error
CVE-2026-11032 2026-06-8 22:39 2026-06-5 Show GitHub Exploit DB Packet Storm
2254 6.5 MEDIUM
Network
google chrome Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium … CWE-457
 Use of Uninitialized Variable
CVE-2026-11033 2026-06-8 22:39 2026-06-5 Show GitHub Exploit DB Packet Storm
2255 6.1 MEDIUM
Network
google chrome Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious netw… CWE-20
 Improper Input Validation 
CVE-2026-11034 2026-06-8 22:38 2026-06-5 Show GitHub Exploit DB Packet Storm
2256 6.1 MEDIUM
Network
cisco webex_meetings A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this… CWE-79
Cross-site Scripting
CVE-2026-20233 2026-06-8 22:36 2026-06-4 Show GitHub Exploit DB Packet Storm
2257 8.1 HIGH
Network
misp misp A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user… CWE-20
 Improper Input Validation 
CVE-2026-10863 2026-06-8 22:35 2026-06-5 Show GitHub Exploit DB Packet Storm
2258 7.3 HIGH
Local
google chrome Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security seve… CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-11035 2026-06-8 22:34 2026-06-5 Show GitHub Exploit DB Packet Storm
2259 6.5 MEDIUM
Network
google chrome Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) CWE-346
 Origin Validation Error
CVE-2026-11036 2026-06-8 22:34 2026-06-5 Show GitHub Exploit DB Packet Storm
2260 6.5 MEDIUM
Network
google chrome Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) CWE-457
 Use of Uninitialized Variable
CVE-2026-11039 2026-06-8 22:31 2026-06-5 Show GitHub Exploit DB Packet Storm