Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200861 9.8 緊急
Network
サムスン - Samsung Note デバイスのソフトウェアの Telecom アプリケーションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-388
エラー処理
CVE-2016-9967 2016-12-26 17:46 2016-09-13 Show GitHub Exploit DB Packet Storm
200862 9.8 緊急
Network
サムスン - Samsung Note デバイスのソフトウェアの Telecom アプリケーションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-388
エラー処理
CVE-2016-9966 2016-12-26 17:46 2016-09-13 Show GitHub Exploit DB Packet Storm
200863 9.8 緊急
Network
サムスン - Samsung Note デバイスのソフトウェアの Telecom アプリケーションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-388
エラー処理
CVE-2016-9965 2016-12-26 17:46 2016-09-13 Show GitHub Exploit DB Packet Storm
200864 7.5 重要
Network
Joomla! - Joomla! の components/com_users/models/registration.php における登録されたユーザアカウントへのアクセス権を取得される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-9838 2016-12-26 17:37 2016-12-13 Show GitHub Exploit DB Packet Storm
200865 7.5 重要
Network
Joomla! - Joomla! の templates/beez3/html/com_content/article/default.php における一般にアクセスできない記事を閲覧される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-9837 2016-12-26 17:37 2016-12-13 Show GitHub Exploit DB Packet Storm
200866 5.3 警告
Network
GNU Project
Debian
Canonical
- Libgcrypt および GnuPG の乱数発生器のミキシング機能における 160 ビットの値を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-6313 2016-12-26 17:12 2016-08-17 Show GitHub Exploit DB Packet Storm
200867 9.9 緊急
Network
PricewaterhouseCoopers (PwC) - SAP Security 用 PwC ACE-ABAP における ABAP インジェクション攻撃を実行される脆弱性 CWE-74
インジェクション
CVE-2016-9832 2016-12-26 16:58 2016-12-7 Show GitHub Exploit DB Packet Storm
200868 9.8 緊急
Network
BMC Software - BMC BladeLogic Server Automation における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2016-4322 2016-12-26 16:57 2016-09-4 Show GitHub Exploit DB Packet Storm
200869 8.8 重要
Network
ImageMagick
オラクル
- ImageMagick の MagickCore/property.c の Get8BIMProperty 関数におけるバッファオーバーフローの脆弱性 CWE-125
境界外読み取り
CVE-2016-6491 2016-12-26 16:55 2016-07-30 Show GitHub Exploit DB Packet Storm
200870 9.8 緊急
Network
ImageMagick
オラクル
- ImageMagick の DCM リーダにおける脆弱性 CWE-20
不適切な入力確認
CVE-2016-5691 2016-12-26 16:55 2016-05-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 - - - ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or adm… New CWE-79
Cross-site Scripting
CVE-2026-47324 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
202 - - - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the o… New CWE-863
 Incorrect Authorization
CVE-2026-44654 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
203 3.7 LOW
Network
- - daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or … New CWE-444
HTTP Request Smuggling
CVE-2026-44546 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
204 5.3 MEDIUM
Network
- - daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote a… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44545 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
205 4.9 MEDIUM
Network
- - alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP cli… New CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-41412 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
206 - - - NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private… New CWE-862
 Missing Authorization
CVE-2026-40571 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
207 - - - Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP… New - CVE-2026-37460 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
208 3.1 LOW
Network
- - An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requ… New CWE-524
 Use of Cache Containing Sensitive Information
CVE-2026-35193 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
209 - - - An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross… New CWE-74
Injection
CVE-2026-10729 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm
210 3.3 LOW
Local
- - A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipul… New CWE-189
CWE-190
Numeric Errors
 Integer Overflow or Wraparound
CVE-2026-10722 2026-06-3 23:16 2026-06-3 Show GitHub Exploit DB Packet Storm