Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 6:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190161 7.8 重要
Local
Bareos GmbH & Co. KG - Bareos における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-14610 2017-10-16 16:57 2017-08-23 Show GitHub Exploit DB Packet Storm
190162 8.8 重要
Network
IBM - IBM Business Process Manager における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-1539 2017-10-16 16:53 2017-09-22 Show GitHub Exploit DB Packet Storm
190163 5.4 警告
Network
IBM - IBM Business Process Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-1531 2017-10-16 16:53 2017-09-22 Show GitHub Exploit DB Packet Storm
190164 5.4 警告
Network
IBM - IBM Business Process Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-1530 2017-10-16 16:53 2017-09-22 Show GitHub Exploit DB Packet Storm
190165 8.1 重要
Network
IBM - IBM Business Process Manager における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2017-1527 2017-10-16 16:53 2017-09-22 Show GitHub Exploit DB Packet Storm
190166 8.8 重要
Network
Kallithea - Kallithea におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-0276 2017-10-16 16:53 2015-04-10 Show GitHub Exploit DB Packet Storm
190167 6.1 警告
Network
IPython development team - IPython におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-4706 2017-10-16 16:44 2015-06-22 Show GitHub Exploit DB Packet Storm
190168 5.5 警告
Local
VMware - 複数の VMware 製品における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-4925 2017-10-16 16:41 2017-09-14 Show GitHub Exploit DB Packet Storm
190169 9.8 緊急
Network
TECNOVISION S.r.l - TecnoVISION DLX Spot Player4 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-12930 2017-10-16 16:39 2017-09-18 Show GitHub Exploit DB Packet Storm
190170 8.8 重要
Network
TECNOVISION S.r.l - TecnoVISION DLX Spot Player4 における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2017-12929 2017-10-16 16:39 2017-09-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 4.3 MEDIUM
Network
jenkins job_import Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of cred… Update CWE-269
 Improper Privilege Management
CVE-2026-48926 2026-06-2 23:49 2026-05-28 Show GitHub Exploit DB Packet Storm
202 8.8 HIGH
Network
- - CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.… New CWE-20
 Improper Input Validation 
CVE-2026-7195 2026-06-2 23:48 2026-06-2 Show GitHub Exploit DB Packet Storm
203 2.5 LOW
Local
mintplexlabs anythingllm AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only … Update CWE-59
Link Following
CVE-2026-45403 2026-06-2 23:48 2026-05-29 Show GitHub Exploit DB Packet Storm
204 8.6 HIGH
Network
- - An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in open… New CWE-369
 Divide By Zero
CVE-2026-37232 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
205 - - - An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=t… New CWE-287
Improper Authentication
CVE-2026-10611 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
206 - - - A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST… New - CVE-2026-35717 2026-06-2 23:47 2026-06-2 Show GitHub Exploit DB Packet Storm
207 - - - Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during… New - CVE-2026-10621 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
208 - - - Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. New - CVE-2026-10622 2026-06-2 23:46 2026-06-2 Show GitHub Exploit DB Packet Storm
209 7.5 HIGH
Network
- - Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to… New CWE-22
Path Traversal
CVE-2026-49136 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
210 8.2 HIGH
Network
- - Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor… New CWE-89
SQL Injection
CVE-2018-25433 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm