Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203681 9.8 緊急
Network
Pivotal Software, Inc. - Pivotal GemFire for PCF の gfsh エンドポイントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-200
CWE-254
CVE-2016-9885 2017-01-23 14:54 2016-12-6 Show GitHub Exploit DB Packet Storm
203682 7.5 重要
Network
Pivotal Software, Inc.
IBM
- Pivotal Spring Security におけるセキュリティ制約を回避される脆弱性 CWE-417
チャネルおよびパスのエラー
CVE-2016-9879 2017-01-23 14:54 2016-12-28 Show GitHub Exploit DB Packet Storm
203683 9.8 緊急
Network
Lexmark - Lexmark Perspective Document Filters の変換機能の Bzip2 構文解析におけるスタックベースのバッファオーバーフローの脆弱性 CWE-787
境界外書き込み
CVE-2016-4336 2017-01-23 12:28 2016-08-6 Show GitHub Exploit DB Packet Storm
203684 7.5 重要
Network
The Chicken Team - CHICKEN の "process-execute" および "process-spawn" プロシージャにおけるリソースの枯渇の脆弱性 CWE-400
リソースの枯渇
CVE-2016-6831 2017-01-23 12:25 2016-08-12 Show GitHub Exploit DB Packet Storm
203685 9.8 緊急
Network
The Chicken Team - CHICKEN Scheme の "process-execute" および "process-spawn" プロシージャにおけるバッファオーバーランの脆弱性 CWE-119
バッファエラー
CVE-2016-6830 2017-01-23 12:25 2016-08-12 Show GitHub Exploit DB Packet Storm
203686 9.8 緊急
Network
Ruby-lang.org - Ruby の Fiddle::Function.new の "初期化" 関数におけるヒープオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-2339 2017-01-23 12:07 2016-06-14 Show GitHub Exploit DB Packet Storm
203687 9.8 緊急
Network
Ruby-lang.org - Ruby の TclTkIp クラスの _cancel_eval メソッドにおける任意のコードを実行される脆弱性 CWE-843
型の取り違え
CVE-2016-2337 2017-01-23 12:07 2016-06-14 Show GitHub Exploit DB Packet Storm
203688 9.8 緊急
Network
Ruby-lang.org - Ruby の WIN32OLE クラスの複数のメソッドにおける任意のコードを実行される脆弱性 CWE-843
型の取り違え
CVE-2016-2336 2017-01-23 12:07 2016-06-14 Show GitHub Exploit DB Packet Storm
203689 6.1 警告
Network
MantisBT Group - MantisBT の MantisBT Filter API におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6837 2017-01-23 11:48 2016-08-15 Show GitHub Exploit DB Packet Storm
203690 5.9 警告
Network
F5 Networks - BIG-IP システムのバーチャルサーバにおける Traffic Management Microkernel を再起動される脆弱性 CWE-20
不適切な入力確認
CVE-2016-9247 2017-01-23 11:45 2016-12-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
11 5.3 MEDIUM
Network
wolfssl wolfssl Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS n… New CWE-295
Improper Certificate Validation 
CVE-2026-10592 2026-06-27 03:55 2026-06-26 Show GitHub Exploit DB Packet Storm
12 7.5 HIGH
Network
wolfssl wolfssl X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application vali… New CWE-295
Improper Certificate Validation 
CVE-2026-11310 2026-06-27 03:54 2026-06-26 Show GitHub Exploit DB Packet Storm
13 7.5 HIGH
Network
microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. New CWE-200
Information Exposure
CVE-2026-47633 2026-06-27 03:54 2026-06-19 Show GitHub Exploit DB Packet Storm
14 7.5 HIGH
Network
wolfssl wolfssl Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Identifier computation reads the trailing 65 bytes of … New CWE-125
Out-of-bounds Read
CVE-2026-12340 2026-06-27 03:54 2026-06-26 Show GitHub Exploit DB Packet Storm
15 7.5 HIGH
Network
wolfssl wolfssl Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so ex… New CWE-393
CWE-787
 Return of Wrong Status Code
 Out-of-bounds Write
CVE-2026-55958 2026-06-27 03:54 2026-06-26 Show GitHub Exploit DB Packet Storm
16 7.5 HIGH
Network
wolfssl wolfssl Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it without performing any … New CWE-295
Improper Certificate Validation 
CVE-2026-55960 2026-06-27 03:54 2026-06-26 Show GitHub Exploit DB Packet Storm
17 5.3 MEDIUM
Network
wolfssl wolfssl Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-s… New CWE-295
Improper Certificate Validation 
CVE-2026-55964 2026-06-27 03:53 2026-06-26 Show GitHub Exploit DB Packet Storm
18 5.5 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is … New CWE-190
 Integer Overflow or Wraparound
CVE-2026-54679 2026-06-27 03:53 2026-06-26 Show GitHub Exploit DB Packet Storm
19 7.1 HIGH
Local
jqlang jq jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds… New CWE-787
 Out-of-bounds Write
CVE-2026-49839 2026-06-27 03:53 2026-06-26 Show GitHub Exploit DB Packet Storm
20 5.5 MEDIUM
Local
jqlang jq jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in deni… New CWE-674
 Uncontrolled Recursion
CVE-2026-47770 2026-06-27 03:53 2026-06-26 Show GitHub Exploit DB Packet Storm