Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199371 10 緊急
Network
modified eCommerce Shopsoftware - modified eCommerce Shopsoftware における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2017-8110 2017-05-31 14:48 2017-04-17 Show GitHub Exploit DB Packet Storm
199372 7.8 重要
Local
SaltStack - SaltStack Salt における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2017-8109 2017-05-31 14:39 2017-04-12 Show GitHub Exploit DB Packet Storm
199373 4.6 警告
Physics
OnePlus - OnePlus 3 および 3T デバイス上で稼動する OxygenOS におけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-5625 2017-05-31 14:28 2017-04-25 Show GitHub Exploit DB Packet Storm
199374 8.2 重要
Network
オラクル - Oracle Fusion Middleware の Oracle WebCenter Sites における Server に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3541 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199375 8.6 重要
Network
オラクル - Oracle Fusion Middleware の Oracle WebCenter Sites における Server に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3540 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199376 7.2 重要
Network
オラクル - Oracle Fusion Middleware の Oracle WebLogic Server における Servlet Runtime に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3531 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199377 7.3 重要
Network
オラクル - Oracle Fusion Middleware の Oracle Service Bus における Web Console Design に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3507 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199378 7.4 重要
Network
オラクル - Oracle Fusion Middleware の Oracle WebLogic Server における Web Services に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3506 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199379 7.5 重要
Network
オラクル - Oracle Fusion Middleware の Oracle Social Network における Android Client に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3499 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
199380 8.6 重要
Network
オラクル - Oracle Fusion Middleware の Oracle Fusion Middleware MapViewer における Map Builder に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-3230 2017-05-31 12:03 2017-04-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
4621 8.2 HIGH
Network
- - CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dan… CWE-94
Code Injection
CVE-2026-41249 2026-06-9 05:17 2026-06-5 Show GitHub Exploit DB Packet Storm
4622 9.8 CRITICAL
Network
- - Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality N… CWE-287
CWE-306
CWE-1390
Improper Authentication
Missing Authentication for Critical Function
 Weak Authentication
CVE-2026-6274 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4623 7.5 HIGH
Network
- - Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers … CWE-22
Path Traversal
CVE-2026-50234 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4624 - - - HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git.php library of the HAXcms PHP backend. The applic… CWE-78
OS Command 
CVE-2026-46394 2026-06-9 04:16 2026-06-6 Show GitHub Exploit DB Packet Storm
4625 - - - OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on eac… CWE-772
CWE-775
 Missing Release of Resource after Effective Lifetime
 Missing Release of File Descriptor or Handle after Effective Lifetime
CVE-2026-45287 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4626 4.3 MEDIUM
Network
- - IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, beca… CWE-650
 Trusting HTTP Permission Methods on the Server Side
CVE-2026-42543 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4627 - - - Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However… CWE-863
 Incorrect Authorization
CVE-2026-41235 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4628 7.8 HIGH
Local
- - A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL. CWE-427
 Uncontrolled Search Path Element
CVE-2026-36574 2026-06-9 04:16 2026-06-4 Show GitHub Exploit DB Packet Storm
4629 9.6 CRITICAL
Network
google chrome Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … CWE-20
 Improper Input Validation 
CVE-2026-11113 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
4630 7.4 HIGH
Network
google chrome Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) CWE-457
 Use of Uninitialized Variable
CVE-2026-10973 2026-06-9 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm