Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
621 7.5 重要
Network
Node.js Foundation undici Node.js Foundationのundiciにおける複数の脆弱性 CWE-400
CWE-770
CVE-2026-9675 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
622 5.9 警告
Network
Node.js Foundation undici Node.js Foundationのundiciにおける重要な情報を含むキャッシュの使用に関する脆弱性 CWE-524
重要な情報を含むキャッシュの使用
CVE-2026-9678 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
623 5.9 警告
Network
Node.js Foundation undici Node.js FoundationのundiciにおけるCRLF インジェクションの脆弱性 CWE-93
CRLF インジェクション
CVE-2026-9679 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
624 7.4 重要
Network
Node.js Foundation undici Node.js Foundationのundiciにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-9697 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
625 8.2 重要
Network
PEVANS (Paul Evans ) Metrics::Any::Adapter::Statsd PEVANS (Paul Evans )のMetrics::Any::Adapter::Statsdにおける複数の脆弱性 CWE-150
CWE-93
CVE-2026-46719
CVE-2026-46720
CVE-2026-46739
CVE-2026-50637
CVE-2026-50638
CVE-2026-50639
2026-06-26 11:51 2026-06-10 Show GitHub Exploit DB Packet Storm
626 9.1 緊急
Network
PEVANS (Paul Evans ) Metrics::Any::Adapter::DogStatsd PEVANS (Paul Evans )のMetrics::Any::Adapter::DogStatsdにおける複数の脆弱性 CWE-150
CWE-93
CVE-2026-50637
CVE-2026-50638
CVE-2026-50639
CVE-2026-9270
2026-06-26 11:51 2026-06-10 Show GitHub Exploit DB Packet Storm
627 6.5 警告
Network
PEVANS (Paul Evans ) Metrics::Any::Adapter::SignalFx PEVANS (Paul Evans )のMetrics::Any::Adapter::SignalFxにおける複数の脆弱性 CWE-150
CWE-93
CVE-2026-50637
CVE-2026-50638
CVE-2026-50639
CVE-2026-9270
2026-06-26 11:51 2026-06-10 Show GitHub Exploit DB Packet Storm
628 7.5 重要
Network
Devolutions UniGetUI DevolutionsのUniGetUIにおける誤って解決された名前や参照の使用に関する脆弱性 CWE-706
誤って解決された名前や参照の使用
CVE-2026-10696 2026-06-26 11:51 2026-06-17 Show GitHub Exploit DB Packet Storm
629 7.8 重要
Local
デル AIOps Collector デルのAIOps Collectorにおけるデフォルトの認証情報の使用に関する脆弱性 CWE-1392
デフォルトの認証情報の使用
CVE-2026-32652 2026-06-26 11:50 2026-06-17 Show GitHub Exploit DB Packet Storm
630 9.1 緊急
Network
UI UniFi OS Server UIのUniFi OS Serverにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-33000 2026-06-26 11:50 2026-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
4421 - - - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture removal failure When aperture_remove_conflicting_pci_devices() fails during probe, … - CVE-2026-52904 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4422 5.3 MEDIUM
Network
- - The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads a… CWE-862
 Missing Authorization
CVE-2026-4986 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4423 - - - In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-backed mounts I/O requests beyond the end of the filesystem should be zeroed ou… - CVE-2026-46329 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4424 6.1 MEDIUM
Network
- - Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parame… CWE-79
Cross-site Scripting
CVE-2026-38579 2026-06-9 23:16 2026-06-6 Show GitHub Exploit DB Packet Storm
4425 - - - A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve pr… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-2638 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4426 8.3 HIGH
Network
- - Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.… CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-11640 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4427 8.8 HIGH
Network
- - Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exe… CWE-78
CWE-77
OS Command 
Command Injection
CVE-2026-11572 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
4428 6.5 MEDIUM
Network
google chrome Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) CWE-693
 Protection Mechanism Failure
CVE-2026-11288 2026-06-9 22:59 2026-06-5 Show GitHub Exploit DB Packet Storm
4429 6.5 MEDIUM
Network
google chrome Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) CWE-1300
CWE-203
 Improper Protection of Physical Side Channels
 Information Exposure Through Discrepancy
CVE-2026-11289 2026-06-9 22:58 2026-06-5 Show GitHub Exploit DB Packet Storm
4430 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulne… CWE-121
Stack-based Buffer Overflow
CVE-2026-36789 2026-06-9 22:57 2026-06-9 Show GitHub Exploit DB Packet Storm