Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3791 6.6 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-35365 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3792 4.4 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける例外的な状態のチェックに関する脆弱性 CWE-754
例外的な状態における不適切なチェック
CVE-2026-35366 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3793 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-35369 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3794 4.4 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-35370 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3795 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-35371 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3796 5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるUNIX Symbolic Link のフォローに関する脆弱性 CWE-61
UNIX Symbolic Link のフォロー
CVE-2026-35372 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3797 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるUnicode エンコーディングの処理に関する脆弱性 CWE-176
Unicode エンコーディングの不適切な処理
CVE-2026-35373 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3798 6.3 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-35374 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3799 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるUnicode エンコーディングの処理に関する脆弱性 CWE-176
Unicode エンコーディングの不適切な処理
CVE-2026-35375 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
3800 5.8 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-35376 2026-05-7 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313471 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function. - CVE-2024-51253 2024-11-5 03:50 2024-11-4 Show GitHub Exploit DB Packet Storm
313472 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function. - CVE-2024-51251 2024-11-5 03:50 2024-11-4 Show GitHub Exploit DB Packet Storm
313473 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function. - CVE-2024-51249 2024-11-5 03:50 2024-11-4 Show GitHub Exploit DB Packet Storm
313474 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function. - CVE-2024-51246 2024-11-5 03:50 2024-11-4 Show GitHub Exploit DB Packet Storm
313475 - - - In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps … - CVE-2024-40659 2024-11-5 03:35 2024-09-11 Show GitHub Exploit DB Packet Storm
313476 - - - An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity. - CVE-2023-20509 2024-11-5 03:35 2024-08-14 Show GitHub Exploit DB Packet Storm
313477 - - - A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands int… - CVE-2024-9287 2024-11-5 03:15 2024-10-23 Show GitHub Exploit DB Packet Storm
313478 - - - Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) aft… - CVE-2024-39341 2024-11-5 02:35 2024-09-24 Show GitHub Exploit DB Packet Storm
313479 - - - In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure wit… - CVE-2024-40656 2024-11-5 02:35 2024-09-11 Show GitHub Exploit DB Packet Storm
313480 - - - Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lane count and speed, potentially leading to a loss of availab… - CVE-2023-31304 2024-11-5 02:35 2024-08-14 Show GitHub Exploit DB Packet Storm