Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200791 5.9 警告
Network
Converse.js - Converse.js の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5858 2017-03-8 15:04 2017-02-1 Show GitHub Exploit DB Packet Storm
200792 5.9 警告
Network
Redsolution, Inc - Xabber の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5606 2017-03-8 15:04 2017-02-9 Show GitHub Exploit DB Packet Storm
200793 5.9 警告
Network
Movim - Movim の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5605 2017-03-8 15:04 2017-01-28 Show GitHub Exploit DB Packet Storm
200794 5.9 警告
Network
mcabber - mcabber の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5604 2017-03-8 15:04 2017-01-26 Show GitHub Exploit DB Packet Storm
200795 5.9 警告
Network
Jitsi - Jitsi の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5603 2017-03-8 15:04 2017-01-27 Show GitHub Exploit DB Packet Storm
200796 5.9 警告
Network
Jappix - jappix の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5602 2017-03-8 15:04 2017-01-27 Show GitHub Exploit DB Packet Storm
200797 5.9 警告
Network
Psi+ Dev Team - Psi+ の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5593 2017-03-8 15:04 2017-01-25 Show GitHub Exploit DB Packet Storm
200798 5.9 警告
Network
profanity - profanity の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5592 2017-03-8 15:04 2017-01-24 Show GitHub Exploit DB Packet Storm
200799 5.9 警告
Network
SleekXMPP project
Slixmpp project
- SleekXMPP および Slixmpp の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5591 2017-03-8 15:04 2017-01-28 Show GitHub Exploit DB Packet Storm
200800 5.9 警告
Network
Georg Lukas - yaxim および Bruno の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5589 2017-03-8 15:04 2017-01-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3141 8.6 HIGH
Network
- - Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow netwo… CWE-924
 Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVE-2019-25719 2026-06-4 01:16 2026-06-2 Show GitHub Exploit DB Packet Storm
3142 5.5 MEDIUM
Local
opentelemetry ebpf_instrumentation OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string o… CWE-20
CWE-248
 Improper Input Validation 
 Uncaught Exception
CVE-2026-45676 2026-06-4 01:08 2026-06-3 Show GitHub Exploit DB Packet Storm
3143 4.2 MEDIUM
Network
redhat build_of_keycloak A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote at… CWE-1288
 Improper Validation of Consistency within Input
CVE-2026-9689 2026-06-4 00:42 2026-05-27 Show GitHub Exploit DB Packet Storm
3144 8.8 HIGH
Network
redhat build_of_keycloak A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token … CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-9704 2026-06-4 00:40 2026-05-27 Show GitHub Exploit DB Packet Storm
3145 6.5 MEDIUM
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper w… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-23638 2026-06-4 00:30 2026-06-2 Show GitHub Exploit DB Packet Storm
3146 8.2 HIGH
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitra… CWE-79
Cross-site Scripting
CVE-2026-24751 2026-06-4 00:29 2026-06-2 Show GitHub Exploit DB Packet Storm
3147 8.2 HIGH
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitra… CWE-79
Cross-site Scripting
CVE-2026-24752 2026-06-4 00:29 2026-06-2 Show GitHub Exploit DB Packet Storm
3148 6.5 MEDIUM
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resou… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-24753 2026-06-4 00:28 2026-06-2 Show GitHub Exploit DB Packet Storm
3149 5.4 MEDIUM
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code… CWE-79
Cross-site Scripting
CVE-2026-24754 2026-06-4 00:28 2026-06-2 Show GitHub Exploit DB Packet Storm
3150 5.4 MEDIUM
Network
accellion kiteworks Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify permi… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-24755 2026-06-4 00:27 2026-06-2 Show GitHub Exploit DB Packet Storm