Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201781 7.3 重要
Network
MODX - MODX Revolution の /connectors/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-10039 2017-01-6 16:49 2016-11-14 Show GitHub Exploit DB Packet Storm
201782 7.3 重要
Network
MODX - MODX Revolution の /connectors/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-10038 2017-01-6 16:49 2016-11-14 Show GitHub Exploit DB Packet Storm
201783 7.3 重要
Network
MODX - MODX Revolution の /connectors/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-10037 2017-01-6 16:49 2016-11-14 Show GitHub Exploit DB Packet Storm
201784 4.4 警告
Local
レッドハット - Red Hat Enterprise Linux などの Linux 実装の sudo のデフォルト設定における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2016-7091 2017-01-6 14:21 2016-11-3 Show GitHub Exploit DB Packet Storm
201785 9.1 緊急
Network
Michel Rodriguez - XML::Twig における外部エンティティを拡張される脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2016-9180 2017-01-6 13:32 2016-09-26 Show GitHub Exploit DB Packet Storm
201786 7.8 重要
Local
OpenJPEG project - OpenJPEG におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9675 2017-01-6 12:36 2016-10-5 Show GitHub Exploit DB Packet Storm
201787 5.3 警告
Network
Digium - Asterisk Open Source および Certified Asterisk の chan_sip チャネルドライバにおけるプロキシの認証なしに Asterisk に INVITE リクエストを許可される脆弱性 CWE-285
不適切な認可
CVE-2016-9938 2017-01-6 11:48 2016-12-8 Show GitHub Exploit DB Packet Storm
201788 7.1 重要
Local
Image-Info project - Image::Info におけるサービス運用妨害 (DoS) の脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2016-9181 2017-01-6 11:18 2016-09-27 Show GitHub Exploit DB Packet Storm
201789 9.8 緊急
Network
Bundler - Bundler における任意の Ruby コードをアプリケーションに挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2016-7954 2017-01-6 11:03 2016-10-5 Show GitHub Exploit DB Packet Storm
201790 7.5 重要
Network
Digium - Asterisk Open Source におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-9937 2017-01-6 09:40 2016-11-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2551 5.5 MEDIUM
Local
google android In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additi… CWE-20
 Improper Input Validation 
CVE-2026-0018 2026-06-3 03:44 2026-06-2 Show GitHub Exploit DB Packet Storm
2552 7.1 HIGH
Network
ibm engineering_lifecycle_management IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter… CWE-611
XXE
CVE-2026-3603 2026-06-3 03:44 2026-05-27 Show GitHub Exploit DB Packet Storm
2553 7.5 HIGH
Network
viewcomponent view_component view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file … CWE-187
 Partial String Comparison
CVE-2026-44837 2026-06-3 03:43 2026-05-27 Show GitHub Exploit DB Packet Storm
2554 3.3 LOW
Local
google android In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disc… CWE-269
 Improper Privilege Management
CVE-2026-0016 2026-06-3 03:41 2026-06-2 Show GitHub Exploit DB Packet Storm
2555 7.5 HIGH
Network
ibm websphere_application_server IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl… CWE-444
HTTP Request Smuggling
CVE-2026-8620 2026-06-3 03:40 2026-05-27 Show GitHub Exploit DB Packet Storm
2556 9.8 CRITICAL
Network
shepherdwind velocity.js Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-44966 2026-06-3 03:40 2026-05-27 Show GitHub Exploit DB Packet Storm
2557 8.2 HIGH
Network
github enterprise_server A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insu… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-9312 2026-06-3 03:31 2026-05-27 Show GitHub Exploit DB Packet Storm
2558 7.5 HIGH
Network
osgeo mapserver MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFil… CWE-129
CWE-476
 Improper Validation of Array Index
 NULL Pointer Dereference
CVE-2026-45104 2026-06-3 03:19 2026-05-28 Show GitHub Exploit DB Packet Storm
2559 5.5 MEDIUM
Local
google android In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-0069 2026-06-3 03:06 2026-06-2 Show GitHub Exploit DB Packet Storm
2560 6.5 MEDIUM
Adjacent
qualcomm fastconnect_7800_firmware
qca7005_firmware
snapdragon_ar1_gen_1_platform_firmware
wcd9380_firmware
wcd9385_firmware
wsa8830_firmware
wsa8832_firmware
wsa8835_firmware
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. CWE-1230
 Exposure of Sensitive Information Through Metadata
CVE-2025-59601 2026-06-3 03:00 2026-06-2 Show GitHub Exploit DB Packet Storm