Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196611 5.4 警告
Network
シスコシステムズ - Cisco Unified Communications Manager の Web ベースの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-3888 2017-05-12 16:47 2017-04-5 Show GitHub Exploit DB Packet Storm
196612 4.9 警告
Network
シスコシステムズ - Cisco Unified Communications Manager の Web インターフェースにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-3886 2017-05-12 16:47 2017-04-5 Show GitHub Exploit DB Packet Storm
196613 5.5 警告
Local
ImageWorsener project - ImageWorsener の libimageworsener.a の imagew-bmp.c における利用可能なメモリ量を消費される脆弱性 CWE-399
リソース管理の問題
CVE-2017-7624 2017-05-12 16:42 2017-04-6 Show GitHub Exploit DB Packet Storm
196614 5.5 警告
Local
ImageWorsener project - ImageWorsener の libimageworsener.a の imagew-miff.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-7623 2017-05-12 16:42 2017-04-6 Show GitHub Exploit DB Packet Storm
196615 6.1 警告
Network
シスコシステムズ - Cisco Registered Envelope Service の Web インターフェースにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-3889 2017-05-12 16:10 2017-04-5 Show GitHub Exploit DB Packet Storm
196616 4.4 警告
Local
シスコシステムズ - Cisco Unified Computing System Manager および Firepower 製品の CLI におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-6602 2017-05-12 15:57 2017-04-5 Show GitHub Exploit DB Packet Storm
196617 7.1 重要
Local
シスコシステムズ - Cisco Unified Computing System Manager および Firepower 製品の CLI におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-6601 2017-05-12 15:57 2017-04-5 Show GitHub Exploit DB Packet Storm
196618 7.8 重要
Local
シスコシステムズ - Cisco Unified Computing System Manager および Firepower 製品の CLI におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-6600 2017-05-12 15:57 2017-04-5 Show GitHub Exploit DB Packet Storm
196619 6.7 警告
Local
シスコシステムズ - Cisco Unified Computing System Manager および Firepower 製品のデバッグプラグイン機能における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-6598 2017-05-12 15:57 2017-04-5 Show GitHub Exploit DB Packet Storm
196620 7.8 重要
Local
シスコシステムズ - Cisco Unified Computing System Manager および Firepower 製品の local-mgmt CLI コマンドにおける OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2017-6597 2017-05-12 15:57 2017-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2401 5.5 MEDIUM
Local
- - A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data. CWE-284
Improper Access Control
CVE-2025-46307 2026-05-27 23:51 2026-05-27 Show GitHub Exploit DB Packet Storm
2402 7.1 HIGH
Network
- - Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n… CWE-862
 Missing Authorization
CVE-2025-14361 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2403 7.3 HIGH
Network
- - A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access cont… CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9580 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2404 4.3 MEDIUM
Network
- - A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site … CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2026-9582 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2405 7.3 HIGH
Network
- - A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql in… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9584 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2406 6.5 MEDIUM
Network
- - A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument I… CWE-862
CWE-863
 Missing Authorization
 Incorrect Authorization
CVE-2026-9603 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2407 4.3 MEDIUM
Network
- - A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improp… CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9604 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2408 7.3 HIGH
Network
- - A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-9606 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2409 6.4 MEDIUM
Network
- - The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endp… CWE-79
Cross-site Scripting
CVE-2026-6565 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
2410 5.3 MEDIUM
Network
- - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-7493 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm