Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197781 5.5 警告
Local
Linux - Linux Kernel の drivers/gpu/drm/vmwgfx/vmwgfx_surface.c の vmw_surface_define_ioctl 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2017-7261 2017-04-26 17:51 2017-03-24 Show GitHub Exploit DB Packet Storm
197782 9.8 緊急
Network
Linux - Linux Kernel の net/ipv6/ip6_gre.c の ip6gre_err 関数における境界外アクセスの脆弱性 CWE-125
境界外読み取り
CVE-2017-5897 2017-04-26 17:51 2017-02-4 Show GitHub Exploit DB Packet Storm
197783 5.5 警告
Local
ImageMagick - ImageMagick の coders/pcx.c の ReadPCXImage 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-7275 2017-04-26 17:49 2017-03-28 Show GitHub Exploit DB Packet Storm
197784 7.8 重要
Local
Artifex Software - Artifex Software の fitz/pixmap.c の fz_subsample_pixmap 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-416
解放済みメモリの使用
CVE-2017-7264 2017-04-26 17:47 2017-02-10 Show GitHub Exploit DB Packet Storm
197785 7.5 重要
Network
Eview - Eview EV-07S GPS トラッカーファームウェアにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2017-5237 2017-04-26 17:02 2017-03-27 Show GitHub Exploit DB Packet Storm
197786 7.5 重要
Network
Eview - Eview EV-07S GPS トラッカーファームウェアにおける暗号強度に関する脆弱性 CWE-326
不適切な暗号強度
CVE-2017-5239 2017-04-26 16:58 2017-03-27 Show GitHub Exploit DB Packet Storm
197787 5.3 警告
Network
Eview - Eview EV-07S GPS トラッカーファームウェアにおけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-5238 2017-04-26 16:58 2017-03-27 Show GitHub Exploit DB Packet Storm
197788 5.4 警告
Network
シーメンス - Siemens RUGGEDCOM ROX I のポート 10000/TCP の統合 Web サーバにおける格納型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6864 2017-04-26 16:53 2017-03-28 Show GitHub Exploit DB Packet Storm
197789 8.8 重要
Network
シーメンス - Siemens RUGGEDCOM ROX I におけるポート10000/TCP で Web インターフェースのアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-2689 2017-04-26 16:53 2017-03-28 Show GitHub Exploit DB Packet Storm
197790 8.8 重要
Network
シーメンス - Siemens RUGGEDCOM ROX I のポート 10000/TCP の統合 Web サーバにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-2688 2017-04-26 16:53 2017-03-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2831 6.3 MEDIUM
Local
- - pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM module loaded into the host process (sudo, login, GDM, GNOME Shell). Display manage… CWE-362
Race Condition
CVE-2026-47270 2026-05-28 22:57 2026-05-28 Show GitHub Exploit DB Packet Storm
2832 6.1 MEDIUM
Network
apache echarts A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0,… CWE-79
Cross-site Scripting
CVE-2026-45249 2026-05-28 22:48 2026-05-25 Show GitHub Exploit DB Packet Storm
2833 6.5 MEDIUM
Network
apache shiro Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1… CWE-384
 Session Fixation
CVE-2026-43827 2026-05-28 22:47 2026-05-26 Show GitHub Exploit DB Packet Storm
2834 6.5 MEDIUM
Network
apache shiro Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommen… CWE-614
 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-43828 2026-05-28 22:45 2026-05-26 Show GitHub Exploit DB Packet Storm
2835 4.3 MEDIUM
Network
- - The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_… CWE-862
 Missing Authorization
CVE-2026-4888 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2836 4.3 MEDIUM
Network
- - The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-9228 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2837 4.3 MEDIUM
Network
- - The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth… CWE-352
 Origin Validation Error
CVE-2026-7533 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2838 6.4 MEDIUM
Network
- - The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due … CWE-79
Cross-site Scripting
CVE-2026-9644 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2839 7.2 HIGH
Network
- - The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to… CWE-79
Cross-site Scripting
CVE-2026-2374 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2840 6.5 MEDIUM
Network
- - The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/searc… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5737 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm