Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4921 7.8 重要
Local
マイクロソフト SQL Server 2019
SQL Server 2025
SQL Server 2016
SQL Server 2022
SQL Server 2017
SQL サーバーの特権の昇格の脆弱性 CWE-89
SQLインジェクション
CVE-2026-32176 2026-05-11 10:58 2026-04-14 Show GitHub Exploit DB Packet Storm
4922 7.5 重要
Network
マイクロソフト .NET
visual studio 2022
.NET のなりすましの脆弱性 CWE-138
特殊要素の不適切な無害化
CVE-2026-32178 2026-05-11 10:58 2026-04-14 Show GitHub Exploit DB Packet Storm
4923 6.5 警告
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-32603 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4924 9.1 緊急
Network
X.Org Foundation
レッドハット
X.Org X Server
Red Hat Enterprise Linux
レッドハット等の複数ベンダの製品における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-34000 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4925 9.1 緊急
Network
X.Org Foundation
レッドハット
X.Org X Server
Red Hat Enterprise Linux
レッドハット等の複数ベンダの製品における不適切な長さの値によるバッファへのアクセスに関する脆弱性 CWE-805
不適切な長さの値によるバッファへのアクセス
CVE-2026-34002 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4926 8.8 重要
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおけるCRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2026-34458 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4927 8.8 重要
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-34459 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4928 7.8 重要
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-34461 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4929 7.8 重要
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける複数の脆弱性 CWE-121
CWE-170
CVE-2026-34462 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
4930 8.8 重要
Local
sandboxie-plus Sandboxie sandboxie-plusのSandboxieにおける複数の脆弱性 CWE-121
CWE-170
CVE-2026-34464 2026-05-11 10:58 2026-05-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315031 - - - Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. … CWE-79
Cross-site Scripting
CVE-2024-51994 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315032 - - - Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2024-51993 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315033 - - - An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet. - CVE-2024-48290 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315034 - - - devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution… CWE-89
SQL Injection
CVE-2024-45794 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315035 - - - A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. The m… CWE-89
CWE-74
SQL Injection
Injection
CVE-2024-10967 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315036 - - - A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The ma… CWE-78
CWE-77
OS Command 
Command Injection
CVE-2024-10966 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315037 - - - An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection. - CVE-2020-11919 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315038 - - - An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in… - CVE-2020-11918 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315039 - - - An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye device… - CVE-2020-11917 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
315040 - - - An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the succ… - CVE-2020-11916 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm