Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194031 9.8 緊急
Network
SQLite - GDAL などの製品で使用される SQLite の ext/rtree/rtree.c の getNodeSize 関数におけるヒープベースのバッファオーバーリードの脆弱性 CWE-119
バッファエラー
CVE-2017-10989 2017-07-31 18:19 2017-07-1 Show GitHub Exploit DB Packet Storm
194032 9.8 緊急
Physics
DBD::mysql project - DBD::mysql における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2017-10788 2017-07-31 18:17 2017-04-14 Show GitHub Exploit DB Packet Storm
194033 7.8 重要
Local
catdoc - catdoc の ole.c の ole_init 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-11110 2017-07-31 18:10 2017-07-7 Show GitHub Exploit DB Packet Storm
194034 7.8 重要
Local
Vim - Vim におけるサービス運用妨害 (DoS) の脆弱性 CWE-416
解放済みメモリの使用
CVE-2017-11109 2017-07-31 18:01 2017-07-8 Show GitHub Exploit DB Packet Storm
194035 7.5 重要
Network
The Tcpdump Group - tcpdump におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-11108 2017-07-31 17:57 2017-07-7 Show GitHub Exploit DB Packet Storm
194036 6.1 警告
Network
Deon George - phpLDAPadmin の htdocs/entry_chooser.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-11107 2017-07-31 17:51 2017-07-8 Show GitHub Exploit DB Packet Storm
194037 7.5 重要
Network
Fabrice Bellard - QEMU の qemu-nbd サーバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2017-9524 2017-07-31 17:49 2017-05-26 Show GitHub Exploit DB Packet Storm
194038 8.8 重要
Network
SWFTools - SWFTools の lib/modules/swftools.c の swf_Relocate() 関数における NULL ポインタデリファレンスを引き起こされる脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-11101 2017-07-31 17:46 2017-06-11 Show GitHub Exploit DB Packet Storm
194039 8.8 重要
Network
SWFTools - SWFTools の lib/rxfswf.c の swf_FoldSprite() 関数における NULL ポインタデリファレンスを引き起こされる脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-11100 2017-07-31 17:46 2017-06-11 Show GitHub Exploit DB Packet Storm
194040 8.8 重要
Network
SWFTools - SWFTools の lib/wav.c の wav_convert2mono() 関数におけるセグメンテーション違反を引き起こされる脆弱性 CWE-20
不適切な入力確認
CVE-2017-11099 2017-07-31 17:46 2017-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3011 7.5 HIGH
Network
archive\ \ Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), … CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-9538 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
3012 7.5 HIGH
Network
- - The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. CWE-524
 Use of Cache Containing Sensitive Information
CVE-2026-48901 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
3013 7.8 HIGH
Local
- - A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca… CWE-787
 Out-of-bounds Write
CVE-2026-48864 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
3014 7.7 HIGH
Network
- - Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45715 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
3015 10.0 CRITICAL
Network
- - Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by de… CWE-15
CWE-78
CWE-306
 External Control of System or Configuration Setting
OS Command 
Missing Authentication for Critical Function
CVE-2026-45087 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
3016 5.0 MEDIUM
Network
- - Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate … CWE-78
CWE-1336
OS Command 
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-44723 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
3017 7.9 HIGH
Local
- - pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption… CWE-59
CWE-287
Link Following
Improper Authentication
CVE-2026-44711 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
3018 7.5 HIGH
Network
archive\ \ Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without va… CWE-59
CWE-732
Link Following
 Incorrect Permission Assignment for Critical Resource
CVE-2026-42497 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
3019 9.1 CRITICAL
Network
archive\ \ Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() with… CWE-59
Link Following
CVE-2026-42496 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
3020 7.3 HIGH
Network
- - Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() functio… CWE-121
Stack-based Buffer Overflow
CVE-2026-38422 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm