Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
51 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11 26h1
Microsoft …
Windows DWM Core ライブラリの特権の昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-42983 2026-06-12 14:51 2026-06-9 Show GitHub Exploit DB Packet Storm
52 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Microsoft Graphics コンポーネントの特権の昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-42986 2026-06-12 14:51 2026-06-9 Show GitHub Exploit DB Packet Storm
53 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2025
Microso…
Windows 展開サービス (WDS) のリモート コード実行 New CWE-416
解放済みメモリの使用
CVE-2026-42987 2026-06-12 14:51 2026-06-9 Show GitHub Exploit DB Packet Storm
54 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Winlogon の特権の昇格の脆弱性 New CWE-59
リンク解釈の問題
CVE-2026-42989 2026-06-12 14:51 2026-06-9 Show GitHub Exploit DB Packet Storm
55 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11 26h1
Microsoft …
Windows プッシュ通知の特権昇格の脆弱性 New CWE-362
CWE-416
CVE-2026-42991 2026-06-12 14:51 2026-06-9 Show GitHub Exploit DB Packet Storm
56 6.5 警告
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける境界外読み取りに関する脆弱性 New CWE-125
境界外読み取り
CVE-2026-43951 2026-06-12 14:51 2026-06-8 Show GitHub Exploit DB Packet Storm
57 5.5 警告
Local
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-44119 2026-06-12 14:51 2026-06-8 Show GitHub Exploit DB Packet Storm
58 7.3 重要
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおけるバッファオーバーリードの脆弱性 New CWE-126
バッファオーバーリード
CVE-2026-44185 2026-06-12 14:51 2026-06-8 Show GitHub Exploit DB Packet Storm
59 7.3 重要
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおける無限ループに関する脆弱性 New CWE-835
無限ループ
CVE-2026-44186 2026-06-12 14:51 2026-06-8 Show GitHub Exploit DB Packet Storm
60 9.8 緊急
Network
Apache Software Foundation Apache HTTP Server Apache Software FoundationのApache HTTP Serverにおけるバッファアンダーフローの脆弱性 New CWE-124
バッファアンダーフロー
CVE-2026-44631 2026-06-12 14:51 2026-06-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319741 4.3 MEDIUM
Network
bplugins html5_video_player The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in… CWE-862
 Missing Authorization
CVE-2024-7721 2024-09-19 03:01 2024-09-11 Show GitHub Exploit DB Packet Storm
319742 7.8 HIGH
Local
ivanti workspace_control An authentication bypass weakness in the message broker service of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges. CWE-306
Missing Authentication for Critical Function
CVE-2024-8012 2024-09-19 02:53 2024-09-11 Show GitHub Exploit DB Packet Storm
319743 7.8 HIGH
Local
ivanti workspace_control DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution. CWE-427
 Uncontrolled Search Path Element
CVE-2024-44107 2024-09-19 02:52 2024-09-11 Show GitHub Exploit DB Packet Storm
319744 7.8 HIGH
Local
ivanti workspace_control Insufficient server-side controls in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges. NVD-CWE-Other
CVE-2024-44106 2024-09-19 02:50 2024-09-11 Show GitHub Exploit DB Packet Storm
319745 7.8 HIGH
Local
ivanti workspace_control Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2024-44105 2024-09-19 02:48 2024-09-11 Show GitHub Exploit DB Packet Storm
319746 7.8 HIGH
Local
ivanti workspace_control An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated … CWE-290
 Authentication Bypass by Spoofing
CVE-2024-44104 2024-09-19 02:33 2024-09-11 Show GitHub Exploit DB Packet Storm
319747 8.8 HIGH
Network
external-secrets external_secrets_operator External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-45041 2024-09-19 02:31 2024-09-10 Show GitHub Exploit DB Packet Storm
319748 9.8 CRITICAL
Network
angeljudesuarez tailoring_management_system A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of … CWE-89
SQL Injection
CVE-2024-8611 2024-09-19 02:24 2024-09-10 Show GitHub Exploit DB Packet Storm
319749 7.8 HIGH
Local
ivanti workspace_control DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges. CWE-426
 Untrusted Search Path
CVE-2024-44103 2024-09-19 02:18 2024-09-11 Show GitHub Exploit DB Packet Storm
319750 6.1 MEDIUM
Network
teleogistic invite_anyone Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a… CWE-79
Cross-site Scripting
CVE-2024-43327 2024-09-19 02:07 2024-08-18 Show GitHub Exploit DB Packet Storm