Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4961 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-43326 2026-05-18 11:28 2026-05-8 Show GitHub Exploit DB Packet Storm
4962 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-43327 2026-05-18 11:28 2026-05-8 Show GitHub Exploit DB Packet Storm
4963 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-43333 2026-05-18 11:28 2026-05-8 Show GitHub Exploit DB Packet Storm
4964 8.8 重要
Adjacent
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43334 2026-05-18 11:28 2026-05-8 Show GitHub Exploit DB Packet Storm
4965 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-43335 2026-05-18 11:28 2026-05-8 Show GitHub Exploit DB Packet Storm
4966 7.5 重要
Network
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43336 2026-05-18 11:27 2026-05-8 Show GitHub Exploit DB Packet Storm
4967 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-43337 2026-05-18 11:27 2026-05-8 Show GitHub Exploit DB Packet Storm
4968 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43338 2026-05-18 11:27 2026-05-8 Show GitHub Exploit DB Packet Storm
4969 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-43339 2026-05-18 11:27 2026-05-8 Show GitHub Exploit DB Packet Storm
4970 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43340 2026-05-18 11:27 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1971 5.3 MEDIUM
Network
- - The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token… - CVE-2026-10530 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1972 6.1 MEDIUM
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… - CVE-2026-4110 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1973 7.1 HIGH
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… CWE-79
Cross-site Scripting
CVE-2026-4259 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1974 7.1 HIGH
Network
- - The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator CWE-79
Cross-site Scripting
CVE-2026-6858 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1975 5.3 MEDIUM
Network
- - The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such a… CWE-862
 Missing Authorization
CVE-2026-7859 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1976 8.8 HIGH
Network
- - The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a cus… CWE-269
 Improper Privilege Management
CVE-2026-8157 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1977 8.2 HIGH
Network
- - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter… CWE-89
SQL Injection
CVE-2017-20255 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1978 8.2 HIGH
Network
- - Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the produc… CWE-89
SQL Injection
CVE-2017-20261 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1979 8.2 HIGH
Network
- - Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET… CWE-89
SQL Injection
CVE-2017-20267 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1980 8.2 HIGH
Network
- - Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id … CWE-89
SQL Injection
CVE-2017-20273 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm