Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4061 6.5 警告
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-8120 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4062 6.5 警告
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-8121 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4063 6.5 警告
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-8122 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4064 6.5 警告
Network
Open5GS Open5GS Open5GSにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-8123 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4065 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. CX12L Pro Firmware Shenzhen Tenda Technology Co.,Ltd.のCX12L Pro Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-8138 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4066 7.8 重要
Local
NAVER Corp. NAVER MYBOX Explorer for Windows NAVER Corp.のNAVER MYBOX Explorer for Windowsにおける不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-8148 2026-05-12 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
4067 7.3 重要
Network
Project Jupyter Jupyter Server Project JupyterのJupyter Serverにおけるアンカーのない正規表現に関する脆弱性 CWE-777
アンカーのない正規表現
CVE-2026-40110 2026-05-12 10:19 2026-05-5 Show GitHub Exploit DB Packet Storm
4068 6.1 警告
Network
HCL Technologies Limited unica
HCL Unica Plan
HCL Unica Segment Central
HCL Unica Centralized Offer Management
HCL Unica Audience Campaign
HCL U…
HCL Technologies Limitedのunica等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-62320 2026-05-12 10:19 2026-03-17 Show GitHub Exploit DB Packet Storm
4069 5.5 警告
Local
ヒューレット・パッカード Samsung Print Service Plugin ヒューレット・パッカードのSamsung Print Service PluginにおけるAndroid アプリケーションコンポーネントの不適切なエクスポートの脆弱性 CWE-926
CWE-noinfo
CVE-2026-3291 2026-05-12 10:19 2026-05-6 Show GitHub Exploit DB Packet Storm
4070 8.8 重要
Network
langflow langflow
Langflow-base
langflowのLangflow-base等の複数製品における複数の脆弱性 CWE-639
CWE-862
CVE-2026-34046 2026-05-12 10:19 2026-03-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313131 7.7 HIGH
Network
linuxfoundation harbor Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the current… CWE-863
 Incorrect Authorization
CVE-2022-31669 2024-11-20 00:20 2024-11-14 Show GitHub Exploit DB Packet Storm
313132 9.8 CRITICAL
Network
backpackforlaravel filemanager FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerabilit… CWE-502
 Deserialization of Untrusted Data
CVE-2024-52306 2024-11-20 00:02 2024-11-14 Show GitHub Exploit DB Packet Storm
313133 9.8 CRITICAL
Network
gogs gogs A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter duri… CWE-77
Command Injection
CVE-2022-1884 2024-11-19 23:47 2024-11-15 Show GitHub Exploit DB Packet Storm
313134 5.4 MEDIUM
Network
usememos memos A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and r… CWE-79
Cross-site Scripting
CVE-2023-0109 2024-11-19 23:44 2024-11-15 Show GitHub Exploit DB Packet Storm
313135 6.5 MEDIUM
Network
wallabag wallabag wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in ve… CWE-352
 Origin Validation Error
CVE-2023-0737 2024-11-19 23:43 2024-11-15 Show GitHub Exploit DB Packet Storm
313136 - - - A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage… - CVE-2024-11075 2024-11-19 23:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313137 - - - Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025. These … - CVE-2024-10204 2024-11-19 23:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313138 - - - Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash th… - CVE-2024-21538 2024-11-19 23:15 2024-11-8 Show GitHub Exploit DB Packet Storm
313139 - - - The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This … CWE-79
Cross-site Scripting
CVE-2024-9830 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313140 6.1 MEDIUM
Network
- - The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This … CWE-79
Cross-site Scripting
CVE-2024-9777 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm