Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3951 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-7956 2026-05-8 12:17 2026-05-6 Show GitHub Exploit DB Packet Storm
3952 5.4 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-7958 2026-05-8 12:17 2026-05-6 Show GitHub Exploit DB Packet Storm
3953 3.1
Network
Google Google Chrome GoogleのGoogle Chromeにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-7959 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3954 5.3 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-7960 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3955 4.3 警告
Adjacent
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7961 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3956 5.4 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7962 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3957 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-7963 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3958 4.2 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7964 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3959 3.1
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7965 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
3960 3.1
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7966 2026-05-8 12:16 2026-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
561 7.5 HIGH
Network
- - Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() functio… New CWE-78
OS Command 
CVE-2026-40519 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
562 7.1 HIGH
Network
- - WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by su… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-49141 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
563 3.5 LOW
Network
- - The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrato… New CWE-79
Cross-site Scripting
CVE-2026-8981 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
564 - - - SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be a… New CWE-89
SQL Injection
CVE-2026-10731 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
565 8.2 HIGH
Network
- - Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST pa… New CWE-89
SQL Injection
CVE-2016-20062 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
566 7.1 HIGH
Network
- - Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attac… New CWE-89
SQL Injection
CVE-2016-20063 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
567 6.2 MEDIUM
Local
- - WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attacke… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2016-20064 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
568 8.2 HIGH
Network
- - Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selec… New CWE-89
SQL Injection
CVE-2016-20065 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
569 8.2 HIGH
Network
- - WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… New CWE-89
SQL Injection
CVE-2017-20243 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
570 8.2 HIGH
Network
- - Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. … New CWE-89
SQL Injection
CVE-2017-20244 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm