Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
461 9.1 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-46896 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
462 9.9 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-46897 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
463 8.1 重要
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-46898 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
464 9.6 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおける複数の脆弱性 New CWE-269
CWE-284
CVE-2026-46899 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
465 9.9 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおける複数の脆弱性 New CWE-269
CWE-284
CVE-2026-46900 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
466 9.9 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおける複数の脆弱性 New CWE-269
CWE-284
CVE-2026-46901 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
467 9.8 緊急
Network
オラクル Oracle Enterprise Command Center Framework オラクルのOracle Enterprise Command Center Frameworkにおける複数の脆弱性 New CWE-284
CWE-306
CVE-2026-46902 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
468 8.8 重要
Network
オラクル JD Edwards EnterpriseOne Tools オラクルのJD Edwards EnterpriseOne Toolsにおける複数の脆弱性 New CWE-269
CWE-287
CWE-306
CVE-2026-46903 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
469 9.8 緊急
Network
オラクル JD Edwards EnterpriseOne Tools オラクルのJD Edwards EnterpriseOne Toolsにおける複数の脆弱性 New CWE-284
CWE-306
CVE-2026-46904 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
470 9.8 緊急
Network
オラクル JD Edwards EnterpriseOne Tools オラクルのJD Edwards EnterpriseOne Toolsにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-46905 2026-06-22 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 25, 2026, 4:04 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
256421 7.5 HIGH
Network
php php The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in … CWE-476
 NULL Pointer Dereference
CVE-2017-6441 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256422 7.8 HIGH
Local
radare radare2 The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified othe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6194 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256423 7.5 HIGH
Network
ruby-lang ruby The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion a… CWE-20
 Improper Input Validation 
CVE-2017-6181 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256424 8.1 HIGH
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. CWE-384
 Session Fixation
CVE-2017-6412 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256425 4.7 MEDIUM
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. CWE-77
Command Injection
CVE-2017-6184 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256426 7.2 HIGH
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NS… CWE-77
Command Injection
CVE-2017-6183 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256427 9.8 CRITICAL
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304. CWE-78
OS Command 
CVE-2017-6182 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256428 9.8 CRITICAL
Network
putty
opensuse_project
opensuse
putty
leap
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6542 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm
256429 6.5 MEDIUM
Network
ntp ntp NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive. CWE-20
 Improper Input Validation 
CVE-2017-6464 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm
256430 6.5 MEDIUM
Network
ntp ntp NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option. CWE-20
 Improper Input Validation 
CVE-2017-6463 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm