Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1661 6.5 警告
Network
Apache Software Foundation Apache CXF Apache Software FoundationのApache CXFにおけるデジタル署名の検証に関する脆弱性 CWE-347
デジタル署名の不適切な検証
CVE-2026-50634 2026-06-15 11:15 2026-06-12 Show GitHub Exploit DB Packet Storm
1662 7.5 重要
Network
Apache Software Foundation Apache CXF Apache Software FoundationのApache CXFにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-50645 2026-06-15 11:15 2026-06-12 Show GitHub Exploit DB Packet Storm
1663 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-53806 2026-06-15 11:15 2026-06-11 Show GitHub Exploit DB Packet Storm
1664 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-53807 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1665 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-53808 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1666 3.8
Local
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-53809 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1667 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-53810 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1668 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-53811 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1669 7.7 重要
Network
OpenClaw OpenClaw OpenClawにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-53812 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
1670 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおける制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2026-53813 2026-06-15 11:14 2026-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
258531 7.5 HIGH
Network
opensuse
sane-backends_project
leap
sane-backends
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet. CWE-200
Information Exposure
CVE-2017-6318 2024-11-21 12:29 2017-03-21 Show GitHub Exploit DB Packet Storm
258532 7.8 HIGH
Local
usbpcap_project usbpcap The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference. CWE-476
 NULL Pointer Dereference
CVE-2017-6178 2024-11-21 12:29 2017-03-21 Show GitHub Exploit DB Packet Storm
258533 7.5 HIGH
Network
qemu qemu Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of se… CWE-120
Classic Buffer Overflow
CVE-2017-6058 2024-11-21 12:29 2017-03-21 Show GitHub Exploit DB Packet Storm
258534 5.3 MEDIUM
Network
typo3 typo3 TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network an… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2017-6370 2024-11-21 12:29 2017-03-18 Show GitHub Exploit DB Packet Storm
258535 7.5 HIGH
Network
efssoft easy_file_sharing_ftp_server Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory. CWE-22
Path Traversal
CVE-2017-6510 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm
258536 8.1 HIGH
Network
drupal drupal A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, a… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2017-6381 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm
258537 7.5 HIGH
Network
drupal drupal Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that use… CWE-352
 Origin Validation Error
CVE-2017-6379 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm
258538 7.5 HIGH
Network
drupal drupal When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass. CWE-863
 Incorrect Authorization
CVE-2017-6377 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm
258539 4.7 MEDIUM
Network
sap businessobjects_financial_consolidation Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET requ… CWE-79
Cross-site Scripting
CVE-2017-6061 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm
258540 6.1 MEDIUM
Network
epson tmnet_webconfig Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1. CWE-79
Cross-site Scripting
CVE-2017-6443 2024-11-21 12:29 2017-03-16 Show GitHub Exploit DB Packet Storm