Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5001 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-43374 2026-05-18 11:26 2026-05-8 Show GitHub Exploit DB Packet Storm
5002 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-43375 2026-05-18 11:26 2026-05-8 Show GitHub Exploit DB Packet Storm
5003 9.8 緊急
Network
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-43376 2026-05-18 11:26 2026-05-8 Show GitHub Exploit DB Packet Storm
5004 8.1 重要
Network
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43377 2026-05-18 11:26 2026-05-8 Show GitHub Exploit DB Packet Storm
5005 9.8 緊急
Network
Apache Software Foundation Apache Tomcat Apache Software FoundationのApache Tomcatにおける認証回避に関する脆弱性 CWE-592
認証回避の問題
CVE-2026-43512 2026-05-18 11:26 2026-05-12 Show GitHub Exploit DB Packet Storm
5006 7.5 重要
Network
Apache Software Foundation Apache Tomcat Apache Software FoundationのApache Tomcatにおける大文字と小文字の区別の不適切な処理に関する脆弱性 CWE-178
大文字と小文字の区別の不適切な処理
CVE-2026-43513 2026-05-18 11:25 2026-05-12 Show GitHub Exploit DB Packet Storm
5007 9.1 緊急
Network
Apache Software Foundation Apache Tomcat Apache Software FoundationのApache Tomcatにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-43515 2026-05-18 11:25 2026-05-12 Show GitHub Exploit DB Packet Storm
5008 7.5 重要
Network
Web Technologies Change Detection Web TechnologiesのChange Detectionにおけるファイル名やパス名の外部制御に関する脆弱性 CWE-73
ファイル名やパス名の外部制御
CVE-2026-43891 2026-05-18 11:25 2026-05-12 Show GitHub Exploit DB Packet Storm
5009 8.7 重要
Network
Daniel Garcia Vaultwarden Daniel GarciaのVaultwardenにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-43912 2026-05-18 11:25 2026-05-11 Show GitHub Exploit DB Packet Storm
5010 9.1 緊急
Network
OPNsense project OPNsense OPNsenseにおける引数の挿入または変更に関する脆弱性 CWE-88
引数の挿入または変更
CVE-2026-44193 2026-05-18 11:25 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1971 5.3 MEDIUM
Network
- - The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token… - CVE-2026-10530 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1972 6.1 MEDIUM
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… - CVE-2026-4110 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1973 7.1 HIGH
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… CWE-79
Cross-site Scripting
CVE-2026-4259 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1974 7.1 HIGH
Network
- - The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator CWE-79
Cross-site Scripting
CVE-2026-6858 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1975 5.3 MEDIUM
Network
- - The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such a… CWE-862
 Missing Authorization
CVE-2026-7859 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1976 8.8 HIGH
Network
- - The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a cus… CWE-269
 Improper Privilege Management
CVE-2026-8157 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1977 8.2 HIGH
Network
- - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter… CWE-89
SQL Injection
CVE-2017-20255 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1978 8.2 HIGH
Network
- - Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the produc… CWE-89
SQL Injection
CVE-2017-20261 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1979 8.2 HIGH
Network
- - Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET… CWE-89
SQL Injection
CVE-2017-20267 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1980 8.2 HIGH
Network
- - Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id … CWE-89
SQL Injection
CVE-2017-20273 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm