Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
71 9.8 緊急
Network
IBM Engineering Lifecycle Management IBMのEngineering Lifecycle Managementにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-3660 2026-06-3 17:02 2026-05-26 Show GitHub Exploit DB Packet Storm
72 7.5 重要
Network
FRRouting Project FRRouting FRRouting ProjectのFRRoutingにおける境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2026-37457 2026-06-3 17:02 2026-05-1 Show GitHub Exploit DB Packet Storm
73 7.2 重要
Network
devcode openstamanager DevcodeのOpenSTAManagerにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 New CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2026-38751 2026-06-3 17:02 2026-05-4 Show GitHub Exploit DB Packet Storm
74 5.5 警告
Local
GPAC GPAC GPACにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-39103 2026-06-3 17:02 2026-05-5 Show GitHub Exploit DB Packet Storm
75 6.1 警告
Network
heartcombo devise heartcomboのdeviseにおけるオープンリダイレクトの脆弱性 New CWE-601
オープンリダイレクト
CVE-2026-40295 2026-06-3 17:02 2026-05-22 Show GitHub Exploit DB Packet Storm
76 5.5 警告
Local
BentoML BentoML BentoMLにおけるリンク解釈に関する脆弱性 New CWE-59
リンク解釈の問題
CVE-2026-40610 2026-06-3 17:02 2026-05-22 Show GitHub Exploit DB Packet Storm
77 4.3 警告
Network
Apache Software Foundation Apache ActiveMQ Artemis
Apache Artemis
Apache Software FoundationのApache ActiveMQ Artemis等の複数製品における不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-40914 2026-06-3 17:02 2026-05-28 Show GitHub Exploit DB Packet Storm
78 7.1 重要
Adjacent
free5gc free5gc free5GCにおけるセキュリティチェックに関する脆弱性 New CWE-358
不適切に実装されたセキュリティチェック
CVE-2026-42081 2026-06-3 17:02 2026-05-27 Show GitHub Exploit DB Packet Storm
79 5.4 警告
Network
Elasticsearch B.V. Kibana Elasticsearch B.V.のKibanaにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42401 2026-06-3 17:01 2026-05-28 Show GitHub Exploit DB Packet Storm
80 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 New CWE-667
不適切なロック
CVE-2026-43061 2026-06-3 17:01 2026-05-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1841 - - - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in … CWE-116
 Improper Encoding or Escaping of Output
CVE-2026-45570 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
1842 5.4 MEDIUM
Network
- - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside… CWE-22
Path Traversal
CVE-2026-45571 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
1843 - - - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o… CWE-180
CWE-345
 Incorrect Behavior Order: Validate Before Canonicalize
 Insufficient Verification of Data Authenticity
CVE-2026-45022 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
1844 - - - Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. Howev… CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-9739 2026-05-30 00:42 2026-05-28 Show GitHub Exploit DB Packet Storm
1845 5.3 MEDIUM
Network
- - opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-45292 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
1846 - - - A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign… CWE-494
 Download of Code Without Integrity Check
CVE-2026-9037 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
1847 - - - A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed… CWE-121
Stack-based Buffer Overflow
CVE-2026-9038 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
1848 - - - A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se… CWE-1188
 Insecure Default Initialization of Resource
CVE-2026-9039 2026-05-30 00:42 2026-05-29 Show GitHub Exploit DB Packet Storm
1849 5.0 MEDIUM
Local
- - GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-read… CWE-116
 Improper Encoding or Escaping of Output
CVE-2026-44972 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm
1850 - - - This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-32996 2026-05-30 00:39 2026-05-28 Show GitHub Exploit DB Packet Storm