Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4821 7.5 重要
Network
Ruby-lang.org Net::IMAP Ruby-lang.orgのNet::IMAPにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-42245 2026-05-20 13:30 2026-05-9 Show GitHub Exploit DB Packet Storm
4822 7.4 重要
Network
Ruby-lang.org Net::IMAP Ruby-lang.orgのNet::IMAPにおける複数の脆弱性 CWE-392
CWE-393
CWE-636
CWE-754
CWE-841
CVE-2026-42246 2026-05-20 13:30 2026-05-9 Show GitHub Exploit DB Packet Storm
4823 9.8 緊急
Network
ollama ollama Ollamaにおけるダウンロードしたコードの完全性検証不備に関する脆弱性 CWE-494
ダウンロードしたコードの完全性検証不備
CVE-2026-42248 2026-05-20 13:30 2026-04-29 Show GitHub Exploit DB Packet Storm
4824 9.8 緊急
Network
ollama ollama Ollamaにおける複数の脆弱性 CWE-22
CWE-494
CVE-2026-42249 2026-05-20 13:30 2026-04-29 Show GitHub Exploit DB Packet Storm
4825 9.8 緊急
Network
Ruby-lang.org Net::IMAP Ruby-lang.orgのNet::IMAPにおける複数の脆弱性 CWE-77
CWE-93
CVE-2026-42257 2026-05-20 13:30 2026-05-9 Show GitHub Exploit DB Packet Storm
4826 9.8 緊急
Network
Ruby-lang.org Net::IMAP Ruby-lang.orgのNet::IMAPにおける複数の脆弱性 CWE-77
CWE-93
CVE-2026-42258 2026-05-20 13:30 2026-05-9 Show GitHub Exploit DB Packet Storm
4827 7.1 重要
Network
Quantum Nous New API Quantum NousのNew APIにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-42339 2026-05-20 13:30 2026-05-8 Show GitHub Exploit DB Packet Storm
4828 9.8 緊急
Network
sentry sentry sentryにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-42354 2026-05-20 13:30 2026-05-8 Show GitHub Exploit DB Packet Storm
4829 5.5 警告
Local
M2-Team NanaZip M2-TeamのNanaZipにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-42355 2026-05-20 13:30 2026-05-12 Show GitHub Exploit DB Packet Storm
4830 5.1 警告
Local
uriparser project uriparser uriparser projectのuriparserにおける数値打ち切り誤差に関する脆弱性 CWE-197
数値打ち切り誤差
CVE-2026-42371 2026-05-20 13:30 2026-04-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2391 - - - AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the passwo… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-56450 2026-06-23 03:16 2026-06-22 Show GitHub Exploit DB Packet Storm
2392 - - - A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers t… CWE-22
Path Traversal
CVE-2026-56448 2026-06-23 03:16 2026-06-22 Show GitHub Exploit DB Packet Storm
2393 - - - Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_i… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-56422 2026-06-23 03:16 2026-06-22 Show GitHub Exploit DB Packet Storm
2394 6.4 MEDIUM
Network
- - The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supp… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-4328 2026-06-23 03:16 2026-06-19 Show GitHub Exploit DB Packet Storm
2395 - - - A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control. CWE-284
Improper Access Control
CVE-2026-4027 2026-06-23 03:16 2026-06-19 Show GitHub Exploit DB Packet Storm
2396 5.8 MEDIUM
Local
- - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when updating a one-time pad file, a temporary file is created using open() without the … CWE-362
Race Condition
CVE-2026-48982 2026-06-23 03:16 2026-06-19 Show GitHub Exploit DB Packet Storm
2397 5.3 MEDIUM
Network
- - The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/str… CWE-862
 Missing Authorization
CVE-2026-3640 2026-06-23 03:16 2026-06-19 Show GitHub Exploit DB Packet Storm
2398 5.5 MEDIUM
Local
- - An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded … CWE-190
 Integer Overflow or Wraparound
CVE-2026-3196 2026-06-23 03:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2399 7.4 HIGH
Local
- - A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially le… CWE-122
Heap-based Buffer Overflow
CVE-2026-3195 2026-06-23 03:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2400 - - - Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript i… CWE-79
Cross-site Scripting
CVE-2026-11943 2026-06-23 03:16 2026-06-23 Show GitHub Exploit DB Packet Storm