Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4351 4.9 警告
Network
キヤノン (複数の製品) キヤノン製プロダクションプリンター、オフィス/スモールオフィス向け複合機における機微な情報を取得可能な脆弱性 CWE-807
セキュリティ決定の信頼できない入力への依存
CVE-2026-1789 2026-05-12 12:34 2026-05-11 Show GitHub Exploit DB Packet Storm
4352 - - - サーバ製品におけるインテル社公表脆弱性(INTEL-SA-01397他)による影響について - CVE-2025-22885
CVE-2025-27560
CVE-2025-27572
CVE-2025-27940
CVE-2025-30513
CVE-2025-31648
CVE-2025-31944
CVE-2025-32007
CVE-2025-32467
2026-05-12 11:50 2026-03-27 Show GitHub Exploit DB Packet Storm
4353 - - - サーバ製品におけるBIOSの脆弱性(CVE-2026-22796)による影響について - CVE-2026-22796 2026-05-12 11:38 2026-04-24 Show GitHub Exploit DB Packet Storm
4354 5.3 警告
Local
Prusa3D PrusaSlicer Prusa3DのPrusaSlicerにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2023-47268 2026-05-12 10:21 2026-05-8 Show GitHub Exploit DB Packet Storm
4355 7.2 重要
Network
HCL Technologies Limited HCL BigFix Service Management (SM) HCL Technologies LimitedのHCL BigFix Service Management (SM)におけるリソースの安全ではないデフォルト値への初期化に関する脆弱性 CWE-1188
リソースの安全ではないデフォルト値への初期化
CVE-2025-31974 2026-05-12 10:21 2026-05-6 Show GitHub Exploit DB Packet Storm
4356 6.1 警告
Network
Project Jupyter Jupyter Server Project JupyterのJupyter Serverにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2025-61669 2026-05-12 10:21 2026-05-5 Show GitHub Exploit DB Packet Storm
4357 8.1 重要
Network
Apache Software Foundation CloudStack Apache Software FoundationのCloudStackにおける不完全なクリーンアップに関する脆弱性 CWE-459
不完全なクリーンアップ
CVE-2025-66467 2026-05-12 10:21 2026-05-8 Show GitHub Exploit DB Packet Storm
4358 7.5 重要
Network
Google Android GoogleのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71253 2026-05-12 10:21 2026-05-6 Show GitHub Exploit DB Packet Storm
4359 7.5 重要
Network
Google Android GoogleのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71254 2026-05-12 10:21 2026-05-6 Show GitHub Exploit DB Packet Storm
4360 7.5 重要
Network
Google Android GoogleのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71255 2026-05-12 10:21 2026-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1171 6.1 MEDIUM
Physics
google chrome Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sever… CWE-269
 Improper Privilege Management
CVE-2026-11229 2026-06-11 04:09 2026-06-5 Show GitHub Exploit DB Packet Storm
1172 4.3 MEDIUM
Network
- - In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR ap… CWE-117
 Improper Output Neutralization for Logs
CVE-2026-20260 2026-06-11 03:36 2026-06-11 Show GitHub Exploit DB Packet Storm
1173 10.0 CRITICAL
Network
- - Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this i… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-47938 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1174 7.3 HIGH
Local
- - OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (e… CWE-78
OS Command 
CVE-2026-11417 2026-06-11 03:35 2026-06-11 Show GitHub Exploit DB Packet Storm
1175 6.4 MEDIUM
Network
- - The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all v… CWE-79
Cross-site Scripting
CVE-2025-8444 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1176 6.4 MEDIUM
Network
- - The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input… CWE-79
Cross-site Scripting
CVE-2026-8613 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1177 4.4 MEDIUM
Network
- - The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output… CWE-79
Cross-site Scripting
CVE-2026-8853 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1178 6.4 MEDIUM
Network
- - The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, an… CWE-79
Cross-site Scripting
CVE-2026-9019 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1179 9.8 CRITICAL
Network
- - The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly rest… CWE-269
 Improper Privilege Management
CVE-2025-6254 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1180 7.5 HIGH
Network
- - The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the use… CWE-89
SQL Injection
CVE-2026-3018 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm