Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4121 9.9 緊急
Network
マイクロソフト Azure Managed Instance for Apache Cassandra Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability CWE-284
不適切なアクセス制御
CVE-2026-33109 2026-05-11 11:11 2026-05-7 Show GitHub Exploit DB Packet Storm
4122 7.5 重要
Network
coredns.io CoreDNS The CoreDNS AuthorsのCoreDNSにおける認証アルゴリズムの不適切な実装に関する脆弱性 CWE-303
認証アルゴリズム上の問題
CVE-2026-33190 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
4123 8.8 重要
Network
FIT2CLOUD SQLBot FIT2CLOUDのSQLBotにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-33324 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
4124 5.3 警告
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33420 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
4125 7.5 重要
Network
coredns.io CoreDNS The CoreDNS AuthorsのCoreDNSにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-33489 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
4126 6.5 警告
Network
マイクロソフト Microsoft Teams Microsoft Team Events Portal Information Disclosure Vulnerability CWE-285
不適切な認可
CVE-2026-33823 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4127 9 緊急
Network
マイクロソフト Azure Managed Instance for Apache Cassandra Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability CWE-20
不適切な入力確認
CVE-2026-33844 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4128 8.2 重要
Network
マイクロソフト Microsoft Partner Center Microsoft Partner Center Spoofing Vulnerability CWE-610
別領域リソースに対する外部からの制御可能な参照
CVE-2026-34327 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
4129 5.3 警告
Network
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける弱いハッシュの使用に関する脆弱性 CWE-328
脆弱なハッシュの使用
CVE-2026-34527 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
4130 6.7 警告
Local
デル data domain operating system
PowerProtect DP Series Appliance
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-35072 2026-05-11 11:10 2026-04-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1251 6.5 MEDIUM
Network
- - Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. CWE-200
Information Exposure
CVE-2026-50508 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1252 8.8 HIGH
Network
- - Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration… CWE-78
OS Command 
CVE-2026-49959 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1253 5.0 MEDIUM
Local
- - Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-49958 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1254 5.3 MEDIUM
Network
- - Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey option… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-49955 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1255 7.8 HIGH
Local
- - Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. CWE-284
Improper Access Control
CVE-2026-49161 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1256 9.8 CRITICAL
Network
- - External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. CWE-73
 External Control of File Name or Path
CVE-2026-47643 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1257 8.1 HIGH
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79
Cross-site Scripting
CVE-2026-47631 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1258 7.0 HIGH
Local
- - Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. CWE-416
 Use After Free
CVE-2026-47293 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1259 7.8 HIGH
Local
- - Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. CWE-94
CWE-829
Code Injection
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-47292 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
1260 6.5 MEDIUM
Network
- - Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. CWE-23
 Relative Path Traversal
CVE-2026-47287 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm