Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
51 7.2 重要
Network
QNAP Systems QuTS hero
QNAP QTS
QNAP SystemsのQNAP QTS等の複数製品におけるNULL ポインタデリファレンスに関する脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2026-24716 2026-06-16 13:38 2026-06-10 Show GitHub Exploit DB Packet Storm
52 7.2 重要
Network
QNAP Systems QuTS hero
QNAP QTS
QNAP SystemsのQNAP QTS等の複数製品におけるOS コマンドインジェクションの脆弱性 New CWE-78
OSコマンド・インジェクション
CVE-2026-24719 2026-06-16 13:38 2026-06-10 Show GitHub Exploit DB Packet Storm
53 5.3 警告
Network
NAVTOR AS NavBox Firmware NAVTOR ASのNavBox Firmwareにおけるエラーメッセージによる情報漏えいに関する脆弱性 New CWE-209
エラーメッセージによる情報漏えい
CVE-2026-2752 2026-06-16 13:38 2026-03-6 Show GitHub Exploit DB Packet Storm
54 7.5 重要
Network
OpenSSL Project OpenSSL OpenSSL ProjectのOpenSSLにおける境界外読み取りに関する脆弱性 New CWE-125
境界外読み取り
CVE-2026-34180 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
55 7.4 重要
Network
OpenSSL Project OpenSSL OpenSSL ProjectのOpenSSLにおけるデータの整合性検証不備に関する脆弱性 New CWE-354
データの整合性検証不備
CVE-2026-34181 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
56 9.1 緊急
Network
OpenSSL Project OpenSSL OpenSSL ProjectのOpenSSLにおけるデータの整合性検証不備に関する脆弱性 New CWE-354
データの整合性検証不備
CVE-2026-34182 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
57 7.5 重要
Network
OpenSSL Project OpenSSL OpenSSL ProjectのOpenSSLにおける不適切に制御された順次メモリ割り当てに関する脆弱性 New CWE-1325
不適切に制御された順次メモリ割り当て
CVE-2026-34183 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
58 5.5 警告
Local
アドビシステムズ C2PA (Coalition for Content Provenance and Authenticity)
(Content Authenticity Initiative) c2pa-web
アドビの(Content Authenticity Initiative) c2pa-web等の複数製品におけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-34657 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
59 7.5 重要
Network
アドビシステムズ C2PA (Coalition for Content Provenance and Authenticity)
(Content Authenticity Initiative) c2pa-web
アドビの(Content Authenticity Initiative) c2pa-web等の複数製品における整数オーバーフローの脆弱性 New CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-34711 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
60 7.5 重要
Network
アドビシステムズ C2PA (Coalition for Content Provenance and Authenticity)
(Content Authenticity Initiative) c2pa-web
アドビの(Content Authenticity Initiative) c2pa-web等の複数製品における入力確認に関する脆弱性 New CWE-20
不適切な入力確認
CVE-2026-34712 2026-06-16 13:38 2026-06-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
310011 - simon_philips com_aardvertiser SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view a… CWE-89
SQL Injection
CVE-2010-4904 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310012 - cubecart cubecart SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. CWE-89
SQL Injection
CVE-2010-4903 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310013 - joomla-clantools clantools Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame paramete… CWE-89
SQL Injection
CVE-2010-4902 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310014 - squiz mysource_matrix Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter. CWE-79
Cross-site Scripting
CVE-2010-4901 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310015 - webmanager-pro cms_webmanager-pro Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. CWE-20
 Improper Input Validation 
CVE-2010-4900 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310016 - webmanager-pro cms_webmanager-pro SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2010-4899 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310017 - gantry-framework com_gantry SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php. CWE-89
SQL Injection
CVE-2010-4898 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310018 - bluecms_project bluecms SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action. CWE-89
SQL Injection
CVE-2010-4897 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310019 - expinion.net member_management_system Cross-site scripting (XSS) vulnerability in admin/index.asp in Member Management System 4.0 allows remote attackers to inject arbitrary web script or HTML via the REF_URL parameter. CWE-79
Cross-site Scripting
CVE-2010-4896 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm
310020 - chillycms chillycms Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE:… CWE-79
Cross-site Scripting
CVE-2010-4895 2024-11-21 10:22 2011-10-8 Show GitHub Exploit DB Packet Storm