Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4441 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-44118 2026-05-11 10:55 2026-05-6 Show GitHub Exploit DB Packet Storm
4442 7.1 重要
Local
gitpython project gitpython gitpython projectのgitpythonにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-44243 2026-05-11 10:55 2026-05-7 Show GitHub Exploit DB Packet Storm
4443 9.1 緊急
Network
The Tor Project Tor The Tor ProjectのTorにおける指定された機能の不適切な提供に関する脆弱性 CWE-684
指定された機能の不適切な提供
CVE-2026-44597 2026-05-11 10:55 2026-05-7 Show GitHub Exploit DB Packet Storm
4444 5.3 警告
Network
The Tor Project Tor The Tor ProjectのTorにおける領域間での誤ったリソース移動に関する脆弱性 CWE-669
領域間での誤ったリソース移動
CVE-2026-44599 2026-05-11 10:55 2026-05-7 Show GitHub Exploit DB Packet Storm
4445 5.3 警告
Network
The Tor Project Tor The Tor ProjectのTorにおける不適切な動作順序に関する脆弱性 CWE-696
不適切な動作順序
CVE-2026-44600 2026-05-11 10:55 2026-05-7 Show GitHub Exploit DB Packet Storm
4446 9.1 緊急
Network
The Tor Project Tor The Tor ProjectのTorにおける境界条件の判定に関する脆弱性 CWE-193
境界条件の判定
CVE-2026-44603 2026-05-11 10:55 2026-05-7 Show GitHub Exploit DB Packet Storm
4447 5.3 警告
Network
Django Software Foundation Django Django Software FoundationのDjangoにおけるレングスパラメーターの不整合による処理に関する脆弱性 CWE-130
レングスパラメーターの不整合による不適切な処理
CVE-2026-5766 2026-05-11 10:55 2026-05-5 Show GitHub Exploit DB Packet Storm
4448 8.8 重要
Network
Ivanti endpoint manager mobile Ivantiのendpoint manager mobileにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-5786 2026-05-11 10:54 2026-05-7 Show GitHub Exploit DB Packet Storm
4449 9.1 緊急
Network
Ivanti endpoint manager mobile Ivantiのendpoint manager mobileにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-5787 2026-05-11 10:54 2026-05-7 Show GitHub Exploit DB Packet Storm
4450 9.8 緊急
Network
Ivanti endpoint manager mobile Ivantiのendpoint manager mobileにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-5788 2026-05-11 10:54 2026-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314441 5.3 MEDIUM
Network
openjsf express A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper… NVD-CWE-noinfo
CVE-2024-10491 2024-11-7 08:08 2024-10-30 Show GitHub Exploit DB Packet Storm
314442 5.4 MEDIUM
Network
joshlobe ultimate_tinymce The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and o… CWE-79
Cross-site Scripting
CVE-2024-8627 2024-11-7 08:06 2024-10-30 Show GitHub Exploit DB Packet Storm
314443 5.5 MEDIUM
Network
ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sens… CWE-611
XXE
CVE-2024-45086 2024-11-7 08:04 2024-11-5 Show GitHub Exploit DB Packet Storm
314444 5.4 MEDIUM
Network
oracle peoplesoft_enterprise_cost_center_common_application_objects Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exp… NVD-CWE-noinfo
CVE-2024-21264 2024-11-7 07:56 2024-10-16 Show GitHub Exploit DB Packet Storm
314445 5.3 MEDIUM
Network
oracle installed_base Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability a… NVD-CWE-noinfo
CVE-2024-21258 2024-11-7 07:56 2024-10-16 Show GitHub Exploit DB Packet Storm
314446 3.0 LOW
Adjacent
oracle hyperion_bi\+ Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allo… NVD-CWE-noinfo
CVE-2024-21257 2024-11-7 07:55 2024-10-16 Show GitHub Exploit DB Packet Storm
314447 8.1 HIGH
Network
oracle process_manufacturing_product_development Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-… NVD-CWE-noinfo
CVE-2024-21250 2024-11-7 07:54 2024-10-16 Show GitHub Exploit DB Packet Storm
314448 4.3 MEDIUM
Network
oracle peoplesoft_enterprise_fin_expenses Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows lo… NVD-CWE-noinfo
CVE-2024-21249 2024-11-7 07:53 2024-10-16 Show GitHub Exploit DB Packet Storm
314449 8.0 HIGH
Network
romadebrian web-sekolah A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler… CWE-89
SQL Injection
CVE-2024-10841 2024-11-7 07:50 2024-11-5 Show GitHub Exploit DB Packet Storm
314450 4.8 MEDIUM
Network
romadebrian web-sekolah A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of… CWE-79
Cross-site Scripting
CVE-2024-10840 2024-11-7 07:49 2024-11-5 Show GitHub Exploit DB Packet Storm