Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1331 8.8 重要
Network
オラクル Oracle E-Business Suite オラクルのOracle E-Business Suiteにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-46837 2026-06-8 11:45 2026-05-28 Show GitHub Exploit DB Packet Storm
1332 9.9 緊急
Network
オラクル REST Data Services オラクルのREST Data Servicesにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46839 2026-06-8 11:45 2026-05-28 Show GitHub Exploit DB Packet Storm
1333 10 緊急
Network
オラクル REST Data Services オラクルのREST Data Servicesにおける複数の脆弱性 CWE-284
CWE-287
CWE-306
CVE-2026-46840 2026-06-8 11:45 2026-05-28 Show GitHub Exploit DB Packet Storm
1334 5.3 警告
Network
オラクル REST Data Services オラクルのREST Data Servicesにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-46841 2026-06-8 11:45 2026-05-28 Show GitHub Exploit DB Packet Storm
1335 8.5 重要
Network
Authentik Security Inc authentik Authentik Security Incのauthentikにおける複数の脆弱性 CWE-20
CWE-347
CVE-2026-47201 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1336 9.8 緊急
Network
Apache Software Foundation Apache Camel Apache Software FoundationのApache Camelにおける大文字と小文字の区別の不適切な処理に関する脆弱性 CWE-178
大文字と小文字の区別の不適切な処理
CVE-2026-47323 2026-06-8 11:45 2026-05-19 Show GitHub Exploit DB Packet Storm
1337 8.1 重要
Network
OpenStack OpenStack Ironic OpenStackのOpenStack Ironicにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-48681 2026-06-8 11:45 2026-06-4 Show GitHub Exploit DB Packet Storm
1338 7.8 重要
Local
Open Source Geospatial Foundation GDAL Open Source Geospatial FoundationのGDALにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-49014 2026-06-8 11:45 2026-05-27 Show GitHub Exploit DB Packet Storm
1339 8.8 重要
Network
Authentik Security Inc authentik Authentik Security Incのauthentikにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-49443 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1340 9.8 緊急
Network
Authentik Security Inc authentik Authentik Security Incのauthentikにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-49448 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
357441 - clever_copy clever_copy Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php. NVD-CWE-Other
CVE-2005-2326 2008-09-6 05:51 2005-07-19 Show GitHub Exploit DB Packet Storm
357442 - laffer laffer PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable. NVD-CWE-Other
CVE-2005-2328 2008-09-6 05:51 2005-07-20 Show GitHub Exploit DB Packet Storm
357443 - - - MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to ac… NVD-CWE-Other
CVE-2005-2329 2008-09-6 05:51 2005-07-20 Show GitHub Exploit DB Packet Storm
357444 - php.warpedweb.net phppageprotect Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php. NVD-CWE-Other
CVE-2005-2332 2008-09-6 05:51 2005-07-20 Show GitHub Exploit DB Packet Storm
357445 - y.sak y.sak Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi. NVD-CWE-Other
CVE-2005-2334 2008-09-6 05:51 2005-07-20 Show GitHub Exploit DB Packet Storm
357446 - msearch unicode_msearch Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via … NVD-CWE-Other
CVE-2005-2339 2008-09-6 05:51 2005-11-22 Show GitHub Exploit DB Packet Storm
357447 - emc navisphere_manager EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot). NVD-CWE-Other
CVE-2005-2358 2008-09-6 05:51 2005-08-16 Show GitHub Exploit DB Packet Storm
357448 - alwil avast_antivirus Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers… NVD-CWE-Other
CVE-2005-2384 2008-09-6 05:51 2005-07-27 Show GitHub Exploit DB Packet Storm
357449 - alwil avast_antivirus Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitr… NVD-CWE-Other
CVE-2005-2385 2008-09-6 05:51 2005-07-27 Show GitHub Exploit DB Packet Storm
357450 - elemental_software cartwiz Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter. NVD-CWE-Other
CVE-2005-2386 2008-09-6 05:51 2005-07-27 Show GitHub Exploit DB Packet Storm