Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199421 6.1 警告
Network
セイコーエプソン株式会社 - EPSON TMNet WebConfig におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6443 2017-04-7 15:04 2017-03-3 Show GitHub Exploit DB Packet Storm
199422 7.8 重要
Local
Artifex Software - Artifex Software, Inc. の MuPDF の mujstest の jstest_main.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-6060 2017-04-7 13:55 2017-02-5 Show GitHub Exploit DB Packet Storm
199423 7.8 重要
Local
OSIsoft - OSIsoft PI Coresight および PI Web API における情報を公開される脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2017-5153 2017-04-6 20:25 2017-01-10 Show GitHub Exploit DB Packet Storm
199424 5.3 警告
Network
Eaton - 特定の Eaton ePDUs のレガシー製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-9357 2017-04-6 20:21 2016-11-16 Show GitHub Exploit DB Packet Storm
199425 6.5 警告
Local
virglrenderer project - virglrenderer の vrend_renderer.c の vrend_create_vertex_elements_state 関数 におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-6386 2017-04-6 20:11 2017-02-28 Show GitHub Exploit DB Packet Storm
199426 6.5 警告
Local
virglrenderer project - virglrenderer の vrend_renderer.c の add_shader_program 関数 におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-6317 2017-04-6 20:11 2017-02-7 Show GitHub Exploit DB Packet Storm
199427 6.5 警告
Local
virglrenderer project - virglrenderer の vrend_decode.c の vrend_decode_reset 関数 におけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-6210 2017-04-6 20:11 2017-02-10 Show GitHub Exploit DB Packet Storm
199428 6.5 警告
Local
virglrenderer project - virglrenderer の Gallium ドライバの TGSI auxiliary モジュール内の tgsi_text.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-6209 2017-04-6 20:11 2017-01-23 Show GitHub Exploit DB Packet Storm
199429 5.5 警告
Local
virglrenderer project - virglrenderer の vrend_renderer.c の vrend_create_vertex_elements_state 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-5994 2017-04-6 20:11 2017-02-7 Show GitHub Exploit DB Packet Storm
199430 6.5 警告
Local
virglrenderer project - virglrenderer の vrend_blitter.c の vrend_renderer_init_blit_ctx 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-5993 2017-04-6 20:11 2017-02-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3671 4.3 MEDIUM
Network
- - A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads … CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-10154 2026-06-2 02:16 2026-05-31 Show GitHub Exploit DB Packet Storm
3672 3.8 LOW
Network
tfa_basic_plugins_project tfa_basic_plugins An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins… CWE-267
 Privilege Defined With Unsafe Actions
CVE-2026-6816 2026-06-2 02:15 2026-05-29 Show GitHub Exploit DB Packet Storm
3673 8.8 HIGH
Network
apache activemq Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-ad… CWE-276
Incorrect Default Permissions 
CVE-2026-49157 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
3674 5.9 MEDIUM
Network
apache activemq
activemq_broker
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurabl… CWE-1230
 Exposure of Sensitive Information Through Metadata
CVE-2026-49270 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
3675 8.8 HIGH
Network
apache activemq
activemq_broker
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrapp… CWE-20
CWE-94
 Improper Input Validation 
Code Injection
CVE-2026-45505 2026-06-2 02:09 2026-06-1 Show GitHub Exploit DB Packet Storm
3676 6.5 MEDIUM
Network
apache airflow A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connect… CWE-200
Information Exposure
CVE-2026-45192 2026-06-2 02:08 2026-06-1 Show GitHub Exploit DB Packet Storm
3677 6.5 MEDIUM
Network
apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to … CWE-22
Path Traversal
CVE-2026-48827 2026-06-2 02:08 2026-06-1 Show GitHub Exploit DB Packet Storm
3678 9.1 CRITICAL
Network
- - The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without … CWE-620
 Unverified Password Change
CVE-2026-5386 2026-06-2 02:07 2026-05-30 Show GitHub Exploit DB Packet Storm
3679 8.4 HIGH
Network
- - A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can injec… CWE-79
Cross-site Scripting
CVE-2026-6824 2026-06-2 02:07 2026-05-30 Show GitHub Exploit DB Packet Storm
3680 9.8 CRITICAL
Network
- - Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials … CWE-798
 Use of Hard-coded Credentials
CVE-2026-7786 2026-06-2 02:07 2026-05-30 Show GitHub Exploit DB Packet Storm