Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
81 9.1 緊急
Network
MessagePack MessagePack MessagePackにおけるリソースの安全ではないデフォルト値への初期化に関する脆弱性 New CWE-1188
リソースの安全ではないデフォルト値への初期化
CVE-2026-48509 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
82 7.5 重要
Network
MessagePack MessagePack MessagePackにおける複数の脆弱性 New CWE-409
CWE-770
CVE-2026-48510 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
83 7.5 重要
Network
MessagePack MessagePack MessagePackにおけるアルゴリズムの複雑さに関する脆弱性 New CWE-407
アルゴリズムの複雑性
CVE-2026-48511 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
84 7.5 重要
Network
MessagePack MessagePack MessagePackにおける再帰制御に関する脆弱性 New CWE-674
不適切な再帰制御
CVE-2026-48512 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
85 7.5 重要
Network
MessagePack MessagePack MessagePackにおける再帰制御に関する脆弱性 New CWE-674
不適切な再帰制御
CVE-2026-48513 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
86 7.5 重要
Network
MessagePack MessagePack MessagePackにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-48514 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
87 7.5 重要
Network
MessagePack MessagePack MessagePackにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-48515 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
88 7.5 重要
Network
MessagePack MessagePack MessagePackにおけるアルゴリズムの複雑さに関する脆弱性 New CWE-407
アルゴリズムの複雑性
CVE-2026-48516 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
89 7.5 重要
Network
MessagePack MessagePack MessagePackにおける複数の脆弱性 New CWE-470
CWE-502
CVE-2026-48517 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
90 9.6 緊急
Network
マイクロソフト Microsoft Exchange Online Microsoft Exchange Online Elevation of Privilege Vulnerability New CWE-862
認証の欠如
CVE-2026-48582 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
256421 7.5 HIGH
Network
php php The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in … CWE-476
 NULL Pointer Dereference
CVE-2017-6441 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256422 7.8 HIGH
Local
radare radare2 The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified othe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6194 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256423 7.5 HIGH
Network
ruby-lang ruby The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion a… CWE-20
 Improper Input Validation 
CVE-2017-6181 2024-11-21 12:29 2017-04-3 Show GitHub Exploit DB Packet Storm
256424 8.1 HIGH
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. CWE-384
 Session Fixation
CVE-2017-6412 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256425 4.7 MEDIUM
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. CWE-77
Command Injection
CVE-2017-6184 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256426 7.2 HIGH
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NS… CWE-77
Command Injection
CVE-2017-6183 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256427 9.8 CRITICAL
Network
sophos web_appliance In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304. CWE-78
OS Command 
CVE-2017-6182 2024-11-21 12:29 2017-03-31 Show GitHub Exploit DB Packet Storm
256428 9.8 CRITICAL
Network
putty
opensuse_project
opensuse
putty
leap
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6542 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm
256429 6.5 MEDIUM
Network
ntp ntp NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive. CWE-20
 Improper Input Validation 
CVE-2017-6464 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm
256430 6.5 MEDIUM
Network
ntp ntp NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option. CWE-20
 Improper Input Validation 
CVE-2017-6463 2024-11-21 12:29 2017-03-28 Show GitHub Exploit DB Packet Storm