Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4411 5.3 警告
Network
MCPHub MCPHub MCPHubにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-13822 2026-05-7 12:07 2026-04-14 Show GitHub Exploit DB Packet Storm
4412 5.3 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2025-14688 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4413 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-36122 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4414 5.3 警告
Network
HCL Technologies Limited HCL AION HCL Technologies LimitedのHCL AIONにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52641 2026-05-7 12:07 2026-04-15 Show GitHub Exploit DB Packet Storm
4415 6.4 警告
Local
レッドハット Ansible Automation Platform レッドハットのAnsible Automation Platformにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57847 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
4416 6.7 警告
Local
レッドハット Red Hat Advanced Cluster Management for Kubernetes レッドハットのRed Hat Advanced Cluster Management for Kubernetesにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57851 2026-05-7 12:07 2026-04-8 Show GitHub Exploit DB Packet Storm
4417 6.5 警告
Network
IBM IBM DB2 IBMのIBM DB2における入力で指定された数量の不適切な検証に関する脆弱性 CWE-1284
入力で指定された数量の不適切な検証
CVE-2026-1577 2026-05-7 12:07 2026-04-30 Show GitHub Exploit DB Packet Storm
4418 5.5 警告
Local
サムスン android サムスンのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21023 2026-05-7 12:06 2026-04-29 Show GitHub Exploit DB Packet Storm
4419 4.8 警告
Network
VMware Spring Security VMwareのSpring SecurityにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-22751 2026-05-7 12:06 2026-04-21 Show GitHub Exploit DB Packet Storm
4420 8.1 重要
Network
フォーティネット FortiAnalyzer Cloud
FortiManager Cloud
フォーティネットのFortiAnalyzer Cloud等の複数製品におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-22828 2026-05-7 12:06 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314511 - - - Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resul… - CVE-2023-20518 2024-11-6 02:35 2024-08-14 Show GitHub Exploit DB Packet Storm
314512 7.8 HIGH
Local
iconics
mitsubishielectric
genesis64
mc_works64
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for ICONICS GENESIS64 version 10.97.3 and prior, Mitsubishi Electric GENESIS64 version 10.97.3 and prio… CWE-276
Incorrect Default Permissions 
CVE-2024-7587 2024-11-6 02:24 2024-10-23 Show GitHub Exploit DB Packet Storm
314513 - - - System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: • Wi-Fi access point credentials t… - CVE-2023-29114 2024-11-6 02:15 2024-11-6 Show GitHub Exploit DB Packet Storm
314514 7.8 HIGH
Local
okta verify The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords asso… CWE-276
Incorrect Default Permissions 
CVE-2024-9191 2024-11-6 02:06 2024-11-2 Show GitHub Exploit DB Packet Storm
314515 8.8 HIGH
Network
esafenet cdg A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The ma… CWE-89
SQL Injection
CVE-2024-10594 2024-11-6 02:05 2024-11-1 Show GitHub Exploit DB Packet Storm
314516 5.4 MEDIUM
Network
webcraftplugins image_map_pro The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6.0.20 due to insuffi… CWE-79
Cross-site Scripting
CVE-2024-9585 2024-11-6 02:05 2024-10-26 Show GitHub Exploit DB Packet Storm
314517 9.8 CRITICAL
Network
esafenet cdg A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the… CWE-89
SQL Injection
CVE-2024-10660 2024-11-6 02:04 2024-11-2 Show GitHub Exploit DB Packet Storm
314518 9.8 CRITICAL
Network
esafenet cdg A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthor… CWE-89
SQL Injection
CVE-2024-10659 2024-11-6 02:04 2024-11-2 Show GitHub Exploit DB Packet Storm
314519 5.4 MEDIUM
Network
webcraftplugins image_map_pro The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to, and including, 6.… CWE-862
 Missing Authorization
CVE-2024-9584 2024-11-6 02:04 2024-10-26 Show GitHub Exploit DB Packet Storm
314520 3.5 LOW
Network
mattermost mattermost Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings. NVD-CWE-Other
CVE-2024-10214 2024-11-6 02:03 2024-10-29 Show GitHub Exploit DB Packet Storm