Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4751 8.8 重要
Network
redis Redis Redis Ltd.のRedisにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-25243 2026-05-8 12:08 2026-05-5 Show GitHub Exploit DB Packet Storm
4752 7.8 重要
Local
クアルコム X2000094 ファームウェア
XG101002 ファームウェア
Snapdragon AR1 Gen 1 ファームウェア
WSA8835 ファームウェア
XG101032 ファームウェア
WSA8830 ファームウェア
fastconnect 7800&nb…
クアルコムのCologne ファームウェア等の複数製品における複数の脆弱性 CWE-749
CWE-787
CVE-2026-25266 2026-05-8 12:08 2026-05-4 Show GitHub Exploit DB Packet Storm
4753 9.8 緊急
Network
クアルコム QCA7005 ファームウェア クアルコムのQCA7005 ファームウェアにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-25293 2026-05-8 12:08 2026-05-4 Show GitHub Exploit DB Packet Storm
4754 10 緊急
Network
vm2 project vm2 vm2 projectのvm2における複数の脆弱性 CWE-693
CWE-94
CVE-2026-26332 2026-05-8 12:08 2026-05-4 Show GitHub Exploit DB Packet Storm
4755 9.8 緊急
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-28474 2026-05-8 12:08 2026-03-5 Show GitHub Exploit DB Packet Storm
4756 9.8 緊急
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-28780 2026-05-8 12:08 2026-05-5 Show GitHub Exploit DB Packet Storm
4757 7.3 重要
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-29168 2026-05-8 12:08 2026-05-5 Show GitHub Exploit DB Packet Storm
4758 4.3 警告
Network
Mozilla Foundation Mozilla Firefox Focus Mozilla FoundationのMozilla Firefox Focusにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-2919 2026-05-8 12:08 2026-03-9 Show GitHub Exploit DB Packet Storm
4759 7.5 重要
Network
OWASP ModSecurity OWASPのModSecurityにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-30923 2026-05-8 12:08 2026-05-5 Show GitHub Exploit DB Packet Storm
4760 8.8 重要
Network
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-31450 2026-05-8 12:08 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
571 - - - Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snaps… New CWE-125
Out-of-bounds Read
CVE-2026-52859 2026-06-12 05:56 2026-06-12 Show GitHub Exploit DB Packet Storm
572 - - - Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as p… New CWE-94
Code Injection
CVE-2026-52860 2026-06-12 05:56 2026-06-12 Show GitHub Exploit DB Packet Storm
573 6.5 MEDIUM
Network
- - A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from… New CWE-787
 Out-of-bounds Write
CVE-2026-53702 2026-06-12 05:56 2026-06-12 Show GitHub Exploit DB Packet Storm
574 6.5 MEDIUM
Network
- - An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partiti… New CWE-787
 Out-of-bounds Write
CVE-2026-53701 2026-06-12 05:56 2026-06-12 Show GitHub Exploit DB Packet Storm
575 - - - Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security c… New CWE-295
Improper Certificate Validation 
CVE-2026-45175 2026-06-12 05:56 2026-06-12 Show GitHub Exploit DB Packet Storm
576 - - - FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can upload a small, malicious PD… New CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-45802 2026-06-12 05:51 2026-06-12 Show GitHub Exploit DB Packet Storm
577 8.1 HIGH
Network
- - SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any… New CWE-312
 Cleartext Storage of Sensitive Information
CVE-2026-46622 2026-06-12 05:50 2026-06-12 Show GitHub Exploit DB Packet Storm
578 5.3 MEDIUM
Network
- - CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to … New CWE-522
 Insufficiently Protected Credentials
CVE-2026-49949 2026-06-12 05:50 2026-06-12 Show GitHub Exploit DB Packet Storm
579 4.3 MEDIUM
Network
- - Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missi… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-53781 2026-06-12 05:50 2026-06-12 Show GitHub Exploit DB Packet Storm
580 7.4 HIGH
Network
- - Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresse… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-53782 2026-06-12 05:50 2026-06-12 Show GitHub Exploit DB Packet Storm