|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 23, 2026, 2:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 691 | 4.9 |
警告
Network |
Apache Software Foundation | Apache DolphinScheduler | Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 New |
CWE-863
不正な認証 |
CVE-2026-41280 | 2026-06-22 11:38 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 692 | 6.1 |
警告
Network |
VMware | Spring Security | VMwareのSpring Securityにおけるオープンリダイレクトの脆弱性 New |
CWE-601
オープンリダイレクト |
CVE-2026-41706 | 2026-06-22 11:37 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 693 | 6.5 |
警告
Network |
Apache Software Foundation | Apache DolphinScheduler | Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 New |
CWE-863
不正な認証 |
CVE-2026-42357 | 2026-06-22 11:37 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 694 | 7.2 |
重要
Network |
OpenStack | OpenStack Ironic | OpenStackのOpenStack Ironicにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 New |
CWE-829
信頼性のない制御領域からの機能の組み込み |
CVE-2026-42510 | 2026-06-22 11:37 | 2026-04-28 | Show | GitHub Exploit DB Packet Storm |
| 695 | 7.5 |
重要
Network |
マイクロソフト |
Microsoft Windows 11 26h1 Microsoft Windows Server 2022 Microsoft Windows 10 22h2 Microsoft Windows 10 1607 Microsoft Wind… |
Windows リモート デスクトップ プロトコル (RDP) の情報漏えいの脆弱性 New |
CWE-125
境界外読み取り |
CVE-2026-42908 | 2026-06-22 11:37 | 2026-06-9 | Show | GitHub Exploit DB Packet Storm |
| 696 | 7.5 |
重要
Network |
マイクロソフト |
Microsoft Windows 11 26h1 Microsoft Windows Server 2022 Microsoft Windows Server 2025 Microsoft Windows 11 25h2 Microsoft … |
リモート デスクトップ クライアントのリモートでコードが実行される脆弱性 New |
CWE-362 CWE-362 CWE-416 CWE-787 |
CVE-2026-42913 | 2026-06-22 11:37 | 2026-06-9 | Show | GitHub Exploit DB Packet Storm |
| 697 | 6.7 |
警告
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 New |
CWE-121
スタックオーバーフロー |
CVE-2026-42919 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 698 | 7.5 |
重要
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品における無限ループに関する脆弱性 New |
CWE-835
無限ループ |
CVE-2026-42920 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 699 | 8.7 |
重要
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品におけるOS コマンドインジェクションの脆弱性 New |
CWE-78
OSコマンド・インジェクション |
CVE-2026-42924 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 700 | 5.8 |
警告
Network |
F5 Networks |
nginx open source NGINX Gateway Fabric NGINX Ingress Controller NGINX Instance Manager |
F5 NetworksのNGINX Gateway Fabric等の複数製品におけるエンコーディングエラーに関する脆弱性 New |
CWE-172
エンコーディングエラー |
CVE-2026-42926 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 23, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 256351 | 5.9 |
MEDIUM
Network |
f5 |
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_application_security_manager big-ip_link_contr… |
In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, PSM software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, when a virtual server uses the standard configuration of HTTP/2 … |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2017-6163 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256352 | 5.9 |
MEDIUM
Network |
f5 |
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_application_security_manager big-ip_link_contr… |
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM… |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2017-6162 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256353 | 5.3 |
MEDIUM
Adjacent |
f5 |
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_application_security_manager big-ip_link_contr… |
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 11.2.1, when ConfigSy… |
CWE-400
Uncontrolled Resource Consumption |
CVE-2017-6161 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256354 | 5.9 |
MEDIUM
Network |
f5 |
big-ip_application_acceleration_manager big-ip_policy_enforcement_manager |
In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (… |
NVD-CWE-noinfo
|
CVE-2017-6160 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256355 | 5.9 |
MEDIUM
Network |
f5 |
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_application_security_manager big-ip_link_contr… |
F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP o… |
NVD-CWE-noinfo
|
CVE-2017-6159 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256356 | 8.1 |
HIGH
Network |
f5 |
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_application_security_manager big-ip_link_contr… |
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration … |
NVD-CWE-noinfo
|
CVE-2017-6157 | 2024-11-21 12:29 | 2017-10-27 | Show | GitHub Exploit DB Packet Storm |
| 256357 | 9.8 |
CRITICAL
Network |
f5 |
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system … |
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms o… |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2017-6165 | 2024-11-21 12:29 | 2017-10-21 | Show | GitHub Exploit DB Packet Storm |
| 256358 | 7.3 |
HIGH
Network |
f5 |
big-ip_link_controller big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_policy_enforcement_manager big-ip_domain_name_system big-ip_… |
iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cook… |
CWE-613
Insufficient Session Expiration |
CVE-2017-6145 | 2024-11-21 12:29 | 2017-10-21 | Show | GitHub Exploit DB Packet Storm |
| 256359 | 7.4 |
HIGH
Network |
f5 | big-ip_policy_enforcement_manager | In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position ma… |
CWE-295
Improper Certificate Validation |
CVE-2017-6144 | 2024-11-21 12:29 | 2017-10-21 | Show | GitHub Exploit DB Packet Storm |
| 256360 | 5.9 |
MEDIUM
Network |
f5 |
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_policy_enforcement_manager big-ip_application_security_manager big-ip_application_acce… |
In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with the Session Ticket op… |
CWE-20
Improper Input Validation |
CVE-2017-6141 | 2024-11-21 12:29 | 2017-10-21 | Show | GitHub Exploit DB Packet Storm |