Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
91 7.2 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるオープンリダイレクトの脆弱性 New CWE-601
オープンリダイレクト
CVE-2026-48895 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
92 5.3 警告
Network
markdown-it project markdown-it markdown-it projectのmarkdown-itにおけるリソースの枯渇に関する脆弱性 New CWE-400
リソースの枯渇
CVE-2026-48988 2026-06-26 11:56 2026-06-17 Show GitHub Exploit DB Packet Storm
93 9.1 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるデータの整合性検証不備に関する脆弱性 New CWE-354
データの整合性検証不備
CVE-2026-49230 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
94 5.4 警告
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるスプーフィングによる認証回避に関する脆弱性 New CWE-290
スプーフィングによる認証回避
CVE-2026-49231 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
95 3.3
Local
pypdf project pypdf pypdf projectのpypdfにおけるアルゴリズムの複雑さに関する脆弱性 New CWE-407
アルゴリズムの複雑性
CVE-2026-49460 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
96 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおけるリソースの枯渇に関する脆弱性 New CWE-400
リソースの枯渇
CVE-2026-49461 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
97 9.8 緊急
Network
litellm litellm LiteLLMにおけるスプーフィングによる認証回避に関する脆弱性 New CWE-290
スプーフィングによる認証回避
CVE-2026-49468 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
98 5.4 警告
Network
Eclipse Foundation Eclipse Open VSX Eclipse FoundationのEclipse Open VSXにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4983 2026-06-26 11:56 2026-06-23 Show GitHub Exploit DB Packet Storm
99 9.3 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-49871 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
100 8.1 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおける認証に関する脆弱性 New CWE-287
不適切な認証
CVE-2026-49872 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
256931 7.8 HIGH
Local
cloudfoundry capi-release An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a reg… NVD-CWE-noinfo
CVE-2017-8036 2024-11-21 12:33 2017-07-25 Show GitHub Exploit DB Packet Storm
256932 9.8 CRITICAL
Network
unicon-software elux The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands with root privileges by inserting commands in a local… CWE-77
Command Injection
CVE-2017-7977 2024-11-21 12:33 2017-07-20 Show GitHub Exploit DB Packet Storm
256933 6.5 MEDIUM
Network
netapp clustered_data_ontap NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on … CWE-200
Information Exposure
CVE-2017-7947 2024-11-21 12:33 2017-07-18 Show GitHub Exploit DB Packet Storm
256934 6.6 MEDIUM
Network
cloudfoundry capi-release
cf-release
routing-release
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issue… CWE-565
 Reliance on Cookies without Validation and Integrity Checking
CVE-2017-8034 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256935 9.8 CRITICAL
Network
dell emc_storage_monitoring_and_reporting
emc_vipr_srm
emc_vnx_monitoring_and_reporting
emc_m\&r
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Pac… CWE-798
 Use of Hard-coded Credentials
CVE-2017-8011 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256936 5.9 MEDIUM
Network
emc rsa_authentication_manager In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to att… CWE-287
Improper Authentication
CVE-2017-8006 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256937 5.4 MEDIUM
Network
emc
rsa
rsa_identity_management_and_governance
rsa_identity_governance_and_lifecycle
rsa_via_lifecycle_and_governance
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle… CWE-79
Cross-site Scripting
CVE-2017-8005 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256938 7.2 HIGH
Network
emc
rsa
rsa_identity_management_and_governance
rsa_identity_governance_and_lifecycle
rsa_via_lifecycle_and_governance
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle … CWE-20
 Improper Input Validation 
CVE-2017-8004 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256939 4.8 MEDIUM
Network
emc rsa_authentication_manager In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database… CWE-79
Cross-site Scripting
CVE-2017-8000 2024-11-21 12:33 2017-07-17 Show GitHub Exploit DB Packet Storm
256940 6.6 MEDIUM
Network
pivotal_software
cloudfoundry
cloud_foundry_uaa
cloud_foundry_uaa_bosh
cloud_foundry_cf
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and oth… CWE-269
 Improper Privilege Management
CVE-2017-8032 2024-11-21 12:33 2017-07-11 Show GitHub Exploit DB Packet Storm