Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1401 7.3 重要
Local
マイクロソフト Microsoft .NET Framework
.NET
.NET の特権の昇格の脆弱性 CWE-190
CWE-20
CWE-noinfo
CVE-2026-35433 2026-06-22 11:38 2026-05-12 Show GitHub Exploit DB Packet Storm
1402 7.1 重要
Local
Linux Foundation Kedro Linux FoundationのKedroにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-3840 2026-06-22 11:38 2026-06-12 Show GitHub Exploit DB Packet Storm
1403 8.8 重要
Network
マイクロソフト SQL Server 2016
SQL Server 2019
SQL Server 2025
SQL Server 2022
SQL Server 2017
SQL Server のリモート コードが実行される脆弱性 CWE-610
CWE-73
CVE-2026-40370 2026-06-22 11:38 2026-05-12 Show GitHub Exploit DB Packet Storm
1404 8.8 重要
Network
マイクロソフト Microsoft Dynamics 365 Microsoft Dynamics 365 (オンプレミス) の特権昇格の脆弱性 CWE-280
CWE-755
CVE-2026-40371 2026-06-22 11:38 2026-06-9 Show GitHub Exploit DB Packet Storm
1405 7.2 重要
Network
VMware Spring Security VMwareのSpring Securityにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-40993 2026-06-22 11:38 2026-06-10 Show GitHub Exploit DB Packet Storm
1406 8.4 重要
Network
マイクロソフト Azure Stack Edge Azure Stack Edge のなりすましの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41098 2026-06-22 11:38 2026-06-9 Show GitHub Exploit DB Packet Storm
1407 5.3 警告
Network
opentelemetry opentelemetry opentelemetryにおける過剰なサイズ値のメモリ割り当てに関する脆弱性 CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-41178 2026-06-22 11:38 2026-06-4 Show GitHub Exploit DB Packet Storm
1408 4.9 警告
Network
Apache Software Foundation Apache DolphinScheduler Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41280 2026-06-22 11:38 2026-06-17 Show GitHub Exploit DB Packet Storm
1409 6.1 警告
Network
VMware Spring Security VMwareのSpring Securityにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-41706 2026-06-22 11:37 2026-06-10 Show GitHub Exploit DB Packet Storm
1410 6.5 警告
Network
Apache Software Foundation Apache DolphinScheduler Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-42357 2026-06-22 11:37 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
258971 6.1 MEDIUM
Network
phpipam phpipam Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/… CWE-79
Cross-site Scripting
CVE-2017-6481 2024-11-21 12:29 2017-03-6 Show GitHub Exploit DB Packet Storm
258972 6.1 MEDIUM
Network
groovel_project cmsgroovel groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter). CWE-79
Cross-site Scripting
CVE-2017-6480 2024-11-21 12:29 2017-03-6 Show GitHub Exploit DB Packet Storm
258973 6.1 MEDIUM
Network
fenix_hosting fenix-open-source FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter). CWE-79
Cross-site Scripting
CVE-2017-6479 2024-11-21 12:29 2017-03-6 Show GitHub Exploit DB Packet Storm
258974 6.1 MEDIUM
Network
mangoswebv4_project mangoswebv4 paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). CWE-79
Cross-site Scripting
CVE-2017-6478 2024-11-21 12:29 2017-03-6 Show GitHub Exploit DB Packet Storm
258975 8.1 HIGH
Network
openelec openelec The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipu… CWE-347
CWE-311
 Improper Verification of Cryptographic Signature
Missing Encryption of Sensitive Data
CVE-2017-6445 2024-11-21 12:29 2017-03-6 Show GitHub Exploit DB Packet Storm
258976 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record … CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-6474 2024-11-21 12:29 2017-03-4 Show GitHub Exploit DB Packet Storm
258977 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between l… CWE-20
 Improper Input Validation 
CVE-2017-6473 2024-11-21 12:29 2017-03-4 Show GitHub Exploit DB Packet Storm
258978 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtm… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-6472 2024-11-21 12:29 2017-03-4 Show GitHub Exploit DB Packet Storm
258979 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validat… CWE-20
 Improper Input Validation 
CVE-2017-6471 2024-11-21 12:29 2017-03-4 Show GitHub Exploit DB Packet Storm
258980 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by cons… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-6470 2024-11-21 12:29 2017-03-4 Show GitHub Exploit DB Packet Storm