Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
721 7.2 重要
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-35326 2026-06-22 11:38 2026-06-17 Show GitHub Exploit DB Packet Storm
722 7.6 重要
Network
オラクル Oracle WebCenter Content オラクルのOracle WebCenter Contentにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-35327 2026-06-22 11:38 2026-06-17 Show GitHub Exploit DB Packet Storm
723 7.3 重要
Local
マイクロソフト Microsoft .NET Framework
.NET
.NET の特権の昇格の脆弱性 CWE-190
CWE-20
CWE-noinfo
CVE-2026-35433 2026-06-22 11:38 2026-05-12 Show GitHub Exploit DB Packet Storm
724 7.1 重要
Local
Linux Foundation Kedro Linux FoundationのKedroにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-3840 2026-06-22 11:38 2026-06-12 Show GitHub Exploit DB Packet Storm
725 8.8 重要
Network
マイクロソフト SQL Server 2016
SQL Server 2019
SQL Server 2025
SQL Server 2022
SQL Server 2017
SQL Server のリモート コードが実行される脆弱性 CWE-610
CWE-73
CVE-2026-40370 2026-06-22 11:38 2026-05-12 Show GitHub Exploit DB Packet Storm
726 8.8 重要
Network
マイクロソフト Microsoft Dynamics 365 Microsoft Dynamics 365 (オンプレミス) の特権昇格の脆弱性 CWE-280
CWE-755
CVE-2026-40371 2026-06-22 11:38 2026-06-9 Show GitHub Exploit DB Packet Storm
727 7.2 重要
Network
VMware Spring Security VMwareのSpring Securityにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40993 2026-06-22 11:38 2026-06-10 Show GitHub Exploit DB Packet Storm
728 8.4 重要
Network
マイクロソフト Azure Stack Edge Azure Stack Edge のなりすましの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41098 2026-06-22 11:38 2026-06-9 Show GitHub Exploit DB Packet Storm
729 5.3 警告
Network
opentelemetry opentelemetry opentelemetryにおける過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-41178 2026-06-22 11:38 2026-06-4 Show GitHub Exploit DB Packet Storm
730 4.9 警告
Network
Apache Software Foundation Apache DolphinScheduler Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41280 2026-06-22 11:38 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320691 6.5 MEDIUM
Network
limesurvey limesurvey A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a… CWE-74
Injection
CVE-2024-42903 2024-09-13 05:20 2024-09-4 Show GitHub Exploit DB Packet Storm
320692 5.4 MEDIUM
Network
xibosignage xibo Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute… CWE-79
Cross-site Scripting
CVE-2024-43412 2024-09-13 05:20 2024-09-4 Show GitHub Exploit DB Packet Storm
320693 6.1 MEDIUM
Network
syspass syspass A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientCon… CWE-79
Cross-site Scripting
CVE-2024-42904 2024-09-13 05:19 2024-09-4 Show GitHub Exploit DB Packet Storm
320694 4.8 MEDIUM
Network
xibosignage xibo Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute… CWE-79
Cross-site Scripting
CVE-2024-43413 2024-09-13 05:18 2024-09-4 Show GitHub Exploit DB Packet Storm
320695 5.4 MEDIUM
Network
cloudcannon pagefinder Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking … CWE-79
Cross-site Scripting
CVE-2024-45389 2024-09-13 05:17 2024-09-4 Show GitHub Exploit DB Packet Storm
320696 - - - Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should reference CVE-2024-45593 instea… - CVE-2024-45845 2024-09-13 05:15 2024-09-10 Show GitHub Exploit DB Packet Storm
320697 9.8 CRITICAL
Network
blakeembrey template @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.… CWE-94
Code Injection
CVE-2024-45390 2024-09-13 05:15 2024-09-4 Show GitHub Exploit DB Packet Storm
320698 7.5 HIGH
Network
tina tina Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search toke… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2024-45391 2024-09-13 05:13 2024-09-4 Show GitHub Exploit DB Packet Storm
320699 4.2 MEDIUM
Physics
yubico yubikey_5c_nfc_firmware
yubikey_5_nfc_firmware
yubikey_5c_firmware
yubikey_5_nano_firmware
yubikey_5c_nano_firmware
yubikey_5ci_firmware
yubikey_5_nfc_fips_firmware
yubikey_5c_nf…
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive eq… CWE-203
 Information Exposure Through Discrepancy
CVE-2024-45678 2024-09-13 05:07 2024-09-4 Show GitHub Exploit DB Packet Storm
320700 4.7 MEDIUM
Network
mozilla firefox_focus Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130. NVD-CWE-noinfo
CVE-2024-8399 2024-09-13 04:45 2024-09-4 Show GitHub Exploit DB Packet Storm