Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5171 7.5 重要
Network
Wireshark Wireshark Wiresharkにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-7379 2026-05-7 12:01 2026-04-30 Show GitHub Exploit DB Packet Storm
5172 6.1 警告
Network
dragonexpert Recent Threads on Index dragonexpertのRecent Threads on Indexにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25309 2026-05-7 12:01 2026-04-29 Show GitHub Exploit DB Packet Storm
5173 6.4 警告
Local
レッドハット Web Terminal レッドハットのWeb Terminalにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57853 2026-05-7 12:01 2026-04-8 Show GitHub Exploit DB Packet Storm
5174 8.5 重要
Network
オラクル Oracle Life Sciences Empirica Signal オラクルのOracle Life Sciences Empirica Signalにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-21997 2026-05-7 12:01 2026-04-21 Show GitHub Exploit DB Packet Storm
5175 9.8 緊急
Network
Arc53 DocsGPT Arc53のDocsGPTにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-26015 2026-05-7 12:01 2026-04-29 Show GitHub Exploit DB Packet Storm
5176 5.5 警告
Local
レッドハット
Sequoia PGP
rpm-sequoia
Red Hat Hardened Images
Red Hat Enterprise Linux
レッドハット等の複数ベンダの製品におけるデジタル署名の検証に関する脆弱性 CWE-347
デジタル署名の不適切な検証
CVE-2026-2625 2026-05-7 12:01 2026-04-3 Show GitHub Exploit DB Packet Storm
5177 10 緊急
Network
scoder Lupa scoderのLupaにおける複数の脆弱性 CWE-284
CWE-639
CVE-2026-34444 2026-05-7 12:01 2026-04-6 Show GitHub Exploit DB Packet Storm
5178 4.7 警告
Local
Moritz Andre Myrseth (moritzmyrz) coursevault-preview Moritz Andre Myrseth (moritzmyrz)のcoursevault-previewにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-35613 2026-05-7 12:01 2026-04-7 Show GitHub Exploit DB Packet Storm
5179 7.8 重要
Local
wkentaro gdown wkentaroのgdownにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40491 2026-05-7 12:01 2026-04-18 Show GitHub Exploit DB Packet Storm
5180 7.4 重要
Network
Skim-rs Skim Skim-rsのSkimにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41414 2026-05-7 12:01 2026-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
61 9.4 CRITICAL
Network
- - Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter t… New CWE-306
Missing Authentication for Critical Function
CVE-2026-49973 2026-06-13 13:17 2026-06-12 Show GitHub Exploit DB Packet Storm
62 7.1 HIGH
Network
- - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on… New CWE-352
 Origin Validation Error
CVE-2026-49396 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm
63 7.7 HIGH
Network
- - Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-47260 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm
64 6.5 MEDIUM
Network
- - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can… New CWE-639
CWE-863
 Authorization Bypass Through User-Controlled Key
 Incorrect Authorization
CVE-2026-47238 2026-06-13 13:17 2026-06-12 Show GitHub Exploit DB Packet Storm
65 5.4 MEDIUM
Network
- - NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) v… New CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2026-47223 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm
66 - - - Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0… New CWE-284
CWE-288
Improper Access Control
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-47200 2026-06-13 13:17 2026-06-12 Show GitHub Exploit DB Packet Storm
67 - - - Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as lon… New CWE-862
 Missing Authorization
CVE-2026-47197 2026-06-13 13:17 2026-06-12 Show GitHub Exploit DB Packet Storm
68 - - - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The diagnostics_channel, … New CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2026-47141 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm
69 10.0 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto_… New CWE-913
 Improper Control of Dynamically-Managed Code Resources
CVE-2026-47131 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm
70 7.7 HIGH
Network
- - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role=… New CWE-863
CWE-918
 Incorrect Authorization
Server-Side Request Forgery (SSRF) 
CVE-2026-46717 2026-06-13 13:17 2026-06-13 Show GitHub Exploit DB Packet Storm