Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202481 7.8 重要
Local
NVIDIA - NVIDIA の Windows GPU ディスプレイドライバの DxgDdiEscape 用カーネルモードレイヤのハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2016-8815 2017-01-4 16:24 2016-11-18 Show GitHub Exploit DB Packet Storm
202482 7.8 重要
Local
NVIDIA - NVIDIA の Windows GPU ディスプレイドライバの DxgDdiEscape 用カーネルモードレイヤのハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-8814 2017-01-4 16:24 2016-11-18 Show GitHub Exploit DB Packet Storm
202483 7.8 重要
Local
NVIDIA - NVIDIA の Windows GPU ディスプレイドライバの DxgDdiEscape 用カーネルモードレイヤのハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-8813 2017-01-4 16:24 2016-11-18 Show GitHub Exploit DB Packet Storm
202484 9.8 緊急
Network
Sensio Labs - Swift Mailer の mail transport における mail コマンドに余分なパラメータを渡される脆弱性 CWE-77
コマンドインジェクション
CVE-2016-10074 2017-01-4 14:02 2016-12-29 Show GitHub Exploit DB Packet Storm
202485 9.8 緊急
Network
Zend Technologies Ltd. - zend-mail コンポーネントおよび Zend Framework の Sendmail アダプタの setFrom 関数における mail コマンドに余分なパラメータを渡される脆弱性 CWE-77
コマンドインジェクション
CVE-2016-10034 2017-01-4 11:43 2016-12-20 Show GitHub Exploit DB Packet Storm
202486 8.1 重要
Network
PHPMailer project - PHPMailer の isMail トランスポートにおける mail コマンドに余分なパラメータを渡される脆弱性 CWE-77
CWE-78
CVE-2016-10045 2017-01-4 11:29 2016-12-28 Show GitHub Exploit DB Packet Storm
202487 8.1 重要
Network
PHPMailer project - PHPMailer の isMail トランスポートの mailSend 関数における mail コマンドに余分なパラメータを渡される脆弱性 CWE-77
CWE-78
CVE-2016-10033 2017-01-4 11:29 2016-12-25 Show GitHub Exploit DB Packet Storm
202488 9.8 緊急
Network
dotCMS - dotCMS の REST API における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-2355 2017-01-4 10:33 2016-04-12 Show GitHub Exploit DB Packet Storm
202489 6.5 警告
Network
Canonical
Apport project
- Apport の悪意のある Apport クラッシュファイルの "RespawnCommand" または "ProcCmdline" フィールドにおける restart コマンドを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-9951 2016-12-28 11:59 2016-12-14 Show GitHub Exploit DB Packet Storm
202490 7.8 重要
Local
NVIDIA - NVIDIA の Windows GPU ディスプレイドライバの DxgDdiEscape 用カーネルモードレイヤのハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-8825 2016-12-28 11:58 2016-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3281 8.2 HIGH
Network
- - Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor… CWE-89
SQL Injection
CVE-2018-25433 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3282 6.5 MEDIUM
Adjacent
- - A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of… CWE-120
Classic Buffer Overflow
CVE-2026-3870 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3283 6.5 MEDIUM
Adjacent
- - A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial… CWE-120
Classic Buffer Overflow
CVE-2026-3871 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3284 - - - LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to th… CWE-280
Improper Handling of Insufficient Permissions or Privileges 
CVE-2026-10549 2026-06-2 23:45 2026-06-2 Show GitHub Exploit DB Packet Storm
3285 8.8 HIGH
Network
- - microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a cra… CWE-121
Stack-based Buffer Overflow
CVE-2026-43623 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm
3286 8.2 HIGH
Network
- - F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-suppli… CWE-22
Path Traversal
CVE-2026-43624 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm
3287 5.9 MEDIUM
Network
- - CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp a… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-43625 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm
3288 7.1 HIGH
Network
- - CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in tempora… CWE-377
 Insecure Temporary File
CVE-2026-49134 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm
3289 7.1 HIGH
Local
- - CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictabl… CWE-59
CWE-377
Link Following
 Insecure Temporary File
CVE-2026-49135 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm
3290 5.0 MEDIUM
Network
- - Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL th… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-49138 2026-06-2 23:43 2026-06-2 Show GitHub Exploit DB Packet Storm