Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
31 6.5 警告
Network
Spring AI Community MCP Security Spring AI CommunityのMCP Securityにおけるサーバサイドのリクエストフォージェリの脆弱性 New CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-45609 2026-06-5 10:51 2026-05-29 Show GitHub Exploit DB Packet Storm
32 5.5 警告
Local
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-20
CWE-248
CVE-2026-45676 2026-06-5 10:51 2026-06-2 Show GitHub Exploit DB Packet Storm
33 7.5 重要
Network
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-20
CWE-754
CVE-2026-45678 2026-06-5 10:51 2026-06-2 Show GitHub Exploit DB Packet Storm
34 6.5 警告
Network
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-117
CWE-532
CVE-2026-45679 2026-06-5 10:51 2026-06-2 Show GitHub Exploit DB Packet Storm
35 7.5 重要
Network
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-400
CWE-834
CVE-2026-45680 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
36 5.9 警告
Network
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-125
CWE-130
CVE-2026-45681 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
37 5.5 警告
Local
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-401
CWE-770
CVE-2026-45682 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
38 3.8
Local
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-127
CWE-200
CVE-2026-45683 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
39 5.3 警告
Local
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-126
CWE-787
CVE-2026-45684 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
40 7.5 重要
Network
opentelemetry eBPF Instrumentation opentelemetryのeBPF Instrumentationにおける複数の脆弱性 New CWE-20
CWE-248
CWE-704
CVE-2026-45685 2026-06-5 10:50 2026-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1931 6.5 MEDIUM
Network
- - A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the arg… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-10190 2026-06-2 02:16 2026-06-1 Show GitHub Exploit DB Packet Storm
1932 4.3 MEDIUM
Network
- - A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads … CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-10154 2026-06-2 02:16 2026-05-31 Show GitHub Exploit DB Packet Storm
1933 3.8 LOW
Network
tfa_basic_plugins_project tfa_basic_plugins An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins… CWE-267
 Privilege Defined With Unsafe Actions
CVE-2026-6816 2026-06-2 02:15 2026-05-29 Show GitHub Exploit DB Packet Storm
1934 8.8 HIGH
Network
apache activemq Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-ad… CWE-276
Incorrect Default Permissions 
CVE-2026-49157 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
1935 5.9 MEDIUM
Network
apache activemq
activemq_broker
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurabl… CWE-1230
 Exposure of Sensitive Information Through Metadata
CVE-2026-49270 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
1936 8.8 HIGH
Network
apache activemq
activemq_broker
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrapp… CWE-20
CWE-94
 Improper Input Validation 
Code Injection
CVE-2026-45505 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
1937 6.5 MEDIUM
Network
apache airflow A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connect… CWE-200
Information Exposure
CVE-2026-45192 2026-06-2 02:08 2026-06-1 Show GitHub Exploit DB Packet Storm
1938 6.5 MEDIUM
Network
apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to … CWE-22
Path Traversal
CVE-2026-48827 2026-06-2 02:08 2026-06-1 Show GitHub Exploit DB Packet Storm
1939 9.1 CRITICAL
Network
- - The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without … CWE-620
 Unverified Password Change
CVE-2026-5386 2026-06-2 02:07 2026-05-30 Show GitHub Exploit DB Packet Storm
1940 8.4 HIGH
Network
- - A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can injec… CWE-79
Cross-site Scripting
CVE-2026-6824 2026-06-2 02:07 2026-05-30 Show GitHub Exploit DB Packet Storm