Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2091 5.3 警告
Local
squirrel-lang squirrel squirrel-langのsquirrelにおける複数の脆弱性 CWE-119
CWE-122
CVE-2026-9541 2026-05-29 11:15 2026-05-26 Show GitHub Exploit DB Packet Storm
2092 7.8 重要
Local
OpenVPN Technologies OpenVPN Connect OpenVPN TechnologiesのOpenVPN Connectにおける複数の脆弱性 CWE-267
CWE-270
CWE-648
CWE-78
CVE-2026-9560 2026-05-29 11:15 2026-05-26 Show GitHub Exploit DB Packet Storm
2093 7.5 重要
Network
Honeywell International Inc. Control Network Module Firmware Honeywell International Inc.のControl Network Module Firmwareにおけるファイルおよびディレクトリ情報の漏えいに関する脆弱性 CWE-538
ファイルおよびディレクトリ情報の漏えい
CVE-2026-5434 2026-05-28 14:45 2026-05-21 Show GitHub Exploit DB Packet Storm
2094 7.5 重要
Network
デル elastic cloud storage デルのelastic cloud storageにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2022-31231 2026-05-28 14:45 2026-05-22 Show GitHub Exploit DB Packet Storm
2095 7.8 重要
Local
Check MK Check MK Check MKにおける制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2024-47091 2026-05-28 14:45 2026-05-13 Show GitHub Exploit DB Packet Storm
2096 5.5 警告
Local
- AutoGPTのAutoGPT Platformにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-32425 2026-05-28 14:44 2026-05-13 Show GitHub Exploit DB Packet Storm
2097 6.5 警告
Network
Neo Technology Neo4j Neo TechnologyのNeo4jにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-1471 2026-05-28 14:44 2026-03-11 Show GitHub Exploit DB Packet Storm
2098 9.8 緊急
Network
Neo Technology Neo4j Neo TechnologyのNeo4jにおける複数の脆弱性 CWE-287
CWE-863
CVE-2026-1524 2026-05-28 14:44 2026-03-11 Show GitHub Exploit DB Packet Storm
2099 5.4 警告
Network
Webmin Project Webmin Webmin ProjectのWebminにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-22678 2026-05-28 14:44 2026-05-21 Show GitHub Exploit DB Packet Storm
2100 8.8 重要
Adjacent
Linux Linux Kernel LinuxのLinux Kernelにおける配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2026-23246 2026-05-28 14:44 2026-03-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
241 5.3 MEDIUM
Network
- - The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relat… New CWE-862
 Missing Authorization
CVE-2026-50244 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
242 7.5 HIGH
Network
- - The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to presen… New CWE-862
 Missing Authorization
CVE-2026-50108 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
243 8.1 HIGH
Network
- - Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset o… New CWE-262
 Not Using Password Aging
CVE-2026-50101 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
244 4.6 MEDIUM
Physics
- - During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled… New CWE-538
 File and Directory Information Exposure
CVE-2026-50099 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
245 - - - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts … New CWE-863
 Incorrect Authorization
CVE-2026-50008 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
246 - - - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema me… New CWE-209
Information Exposure Through an Error Message
CVE-2026-47248 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
247 4.3 MEDIUM
Network
- - Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API… New CWE-863
 Incorrect Authorization
CVE-2026-47236 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
248 - - - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-kn… New CWE-1333
 Inefficient Regular Expression Complexity
CVE-2026-47138 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
249 8.8 HIGH
Network
- - A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints vali… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-42947 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm
250 5.3 MEDIUM
Network
- - Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endp… New CWE-340
 Generation of Predictable Numbers or Identifiers
CVE-2026-42932 2026-06-13 04:16 2026-06-13 Show GitHub Exploit DB Packet Storm