Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5151 3.7
Network
Apache Software Foundation Apache Tomcat Apache Software FoundationのApache Tomcatにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-43514 2026-05-18 12:13 2026-05-12 Show GitHub Exploit DB Packet Storm
5152 7.5 重要
Network
- アップルのmacOSにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-43652 2026-05-18 12:13 2026-05-11 Show GitHub Exploit DB Packet Storm
5153 7.5 重要
Network
アップル visionos
watchOS
iOS
tvOS
iPadOS
アップルのiPadOS等の複数製品における認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-43654 2026-05-18 12:13 2026-05-11 Show GitHub Exploit DB Packet Storm
5154 10 緊急
Network
vm2 project vm2 vm2 projectのvm2におけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-43997 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5155 8.5 重要
Network
vm2 project vm2 vm2 projectのvm2におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-43998 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5156 9.9 緊急
Network
vm2 project vm2 vm2 projectのvm2における不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-43999 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5157 7.2 重要
Network
vm2 project vm2 vm2 projectのvm2における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-44000 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5158 8.6 重要
Network
vm2 project vm2 vm2 projectのvm2におけるキャッチされない例外に関する脆弱性 CWE-248
キャッチされない例外
CVE-2026-44001 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5159 5.8 警告
Network
vm2 project vm2 vm2 projectのvm2におけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2026-44002 2026-05-18 12:13 2026-05-13 Show GitHub Exploit DB Packet Storm
5160 5.8 警告
Network
vm2 project vm2 vm2 projectのvm2における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-44003 2026-05-18 12:12 2026-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1781 8.3 HIGH
Network
- - Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-56215 2026-06-25 04:17 2026-06-20 Show GitHub Exploit DB Packet Storm
1782 4.9 MEDIUM
Network
- - Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not u… CWE-287
Improper Authentication
CVE-2026-56080 2026-06-25 04:17 2026-06-20 Show GitHub Exploit DB Packet Storm
1783 - - - A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. CWE-284
Improper Access Control
CVE-2026-48908 2026-06-25 04:17 2026-06-20 Show GitHub Exploit DB Packet Storm
1784 9.8 CRITICAL
Network
litellm litellm LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0. CWE-290
 Authentication Bypass by Spoofing
CVE-2026-49468 2026-06-25 04:16 2026-06-23 Show GitHub Exploit DB Packet Storm
1785 7.7 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does … CWE-22
CWE-918
Path Traversal
Server-Side Request Forgery (SSRF) 
CVE-2026-54017 2026-06-25 04:04 2026-06-19 Show GitHub Exploit DB Packet Storm
1786 9.8 CRITICAL
Network
ibm i IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execut… CWE-94
Code Injection
CVE-2026-9072 2026-06-25 02:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1787 7.3 HIGH
Network
- - The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable v… CWE-79
Cross-site Scripting
CVE-2026-9029 2026-06-25 02:17 2026-06-22 Show GitHub Exploit DB Packet Storm
1788 8.8 HIGH
Adjacent
ibm i IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnera… CWE-94
Code Injection
CVE-2026-8858 2026-06-25 02:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1789 9.6 CRITICAL
Network
- - SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve… CWE-79
Cross-site Scripting
CVE-2026-56397 2026-06-25 02:17 2026-06-21 Show GitHub Exploit DB Packet Storm
1790 4.3 MEDIUM
Network
- - Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an att… CWE-862
 Missing Authorization
CVE-2026-56384 2026-06-25 02:17 2026-06-21 Show GitHub Exploit DB Packet Storm