Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1381 5.5 警告
Local
ERLANG Erl Interface
Erlang/OTP
ERLANGのErl Interface等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-49760 2026-06-16 13:40 2026-06-10 Show GitHub Exploit DB Packet Storm
1382 5.7 警告
Adjacent
nuxt nuxt/webpack-builder
nuxt/rspack-builder
Nuxtのnuxt/rspack-builder等の複数製品における危険なメソッドや機能の公開に関する脆弱性 CWE-749
危険なメソッドや機能の公開
CVE-2026-49993 2026-06-16 13:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1383 9.8 緊急
Network
jmespath project jmespath JMESPathにおける複数の脆弱性 CWE-116
CWE-20
CWE-94
CVE-2026-54133 2026-06-16 13:39 2026-06-12 Show GitHub Exploit DB Packet Storm
1384 5.5 警告
Local
- アップルのmacOSにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-24165 2026-06-16 13:39 2026-06-11 Show GitHub Exploit DB Packet Storm
1385 5.5 警告
Local
- アップルのmacOSにおけるUNIX Symbolic Link のフォローに関する脆弱性 CWE-61
UNIX Symbolic Link のフォロー
CVE-2025-43278 2026-06-16 13:39 2026-06-11 Show GitHub Exploit DB Packet Storm
1386 5.5 警告
Local
- アップルのmacOSにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2025-46313 2026-06-16 13:39 2026-06-11 Show GitHub Exploit DB Packet Storm
1387 7.2 重要
Network
QNAP Systems QuTS hero QNAP SystemsのQuTS heroにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2025-62850 2026-06-16 13:39 2026-06-10 Show GitHub Exploit DB Packet Storm
1388 7.2 重要
Network
QNAP Systems QuTS hero
QNAP QTS
QNAP SystemsのQNAP QTS等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2025-66273 2026-06-16 13:39 2026-06-10 Show GitHub Exploit DB Packet Storm
1389 7.2 重要
Network
QNAP Systems QuTS hero
QNAP QTS
QNAP SystemsのQNAP QTS等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2025-66279 2026-06-16 13:39 2026-06-10 Show GitHub Exploit DB Packet Storm
1390 7.2 重要
Network
QNAP Systems QuTS hero
QNAP QTS
QNAP SystemsのQNAP QTS等の複数製品における複数の脆弱性 CWE-121
CWE-190
CVE-2025-66280 2026-06-16 13:39 2026-06-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
257471 9.8 CRITICAL
Network
grpc grpc Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c. CWE-787
 Out-of-bounds Write
CVE-2017-7860 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257472 9.8 CRITICAL
Network
ffmpeg ffmpeg FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c. CWE-787
 Out-of-bounds Write
CVE-2017-7859 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257473 9.8 CRITICAL
Network
freetype freetype FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c. CWE-787
 Out-of-bounds Write
CVE-2017-7858 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257474 9.8 CRITICAL
Network
freetype freetype FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfob… CWE-787
 Out-of-bounds Write
CVE-2017-7857 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257475 9.8 CRITICAL
Network
libreoffice libreoffice LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx. CWE-787
 Out-of-bounds Write
CVE-2017-7856 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257476 6.1 MEDIUM
Network
concretecms concrete_cms concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings… CWE-79
Cross-site Scripting
CVE-2017-7725 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257477 5.5 MEDIUM
Local
radare radare2 The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file. CWE-125
Out-of-bounds Read
CVE-2017-7854 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257478 7.5 HIGH
Network
gnu osip In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-7853 2024-11-21 12:32 2017-04-14 Show GitHub Exploit DB Packet Storm
257479 9.8 CRITICAL
Network
smart_related_articles_project smart_related_articles The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability). CWE-89
SQL Injection
CVE-2017-7628 2024-11-21 12:32 2017-04-13 Show GitHub Exploit DB Packet Storm
257480 5.3 MEDIUM
Network
smart_related_articles_project smart_related_articles The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check). NVD-CWE-noinfo
CVE-2017-7627 2024-11-21 12:32 2017-04-13 Show GitHub Exploit DB Packet Storm