Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2121 6.1 警告
Network
VMware Spring Framework VMwareのSpring Frameworkにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41846 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2122 5.3 警告
Network
VMware Spring Framework VMwareのSpring Frameworkにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-41847 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2123 7.5 重要
Network
VMware Spring Framework VMwareのSpring Frameworkにおける非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2026-41848 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2124 5.3 警告
Network
VMware Spring Framework VMwareのSpring Frameworkにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41852 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2125 5.1 警告
Local
ImageMagick ImageMagick ImageMagickにおける複数の脆弱性 CWE-125
CWE-191
CVE-2026-42326 2026-06-12 14:53 2026-06-10 Show GitHub Exploit DB Packet Storm
2126 7.5 重要
Network
Svelte project Svelte Svelte projectのSvelteにおける非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2026-42567 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2127 7.5 重要
Network
Svelte project devalue Svelte projectのdevalueにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42570 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2128 6.1 警告
Network
Svelte project Svelte Svelte projectのSvelteにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42573 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2129 6.1 警告
Network
Svelte project Svelte Svelte projectのSvelteにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42599 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
2130 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Windows 管理者保護のセキュリティ機能バイパスの脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-42829 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
4441 7.5 HIGH
Network
- - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. CWE-125
Out-of-bounds Read
CVE-2026-45639 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4442 7.5 HIGH
Network
- - Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. CWE-400
 Uncontrolled Resource Consumption
CVE-2026-45591 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4443 7.5 HIGH
Network
- - Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. CWE-94
Code Injection
CVE-2026-45583 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4444 6.1 MEDIUM
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79
Cross-site Scripting
CVE-2026-45500 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4445 6.2 MEDIUM
Local
- - Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. CWE-59
Link Following
CVE-2026-45491 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4446 7.8 HIGH
Local
- - Improper authorization in .NET allows an authorized attacker to elevate privileges locally. CWE-285
Improper Authorization
CVE-2026-45490 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4447 4.6 MEDIUM
Network
- - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. CWE-79
Cross-site Scripting
CVE-2026-45483 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4448 8.4 HIGH
Local
- - Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. CWE-22
Path Traversal
CVE-2026-45482 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4449 8.2 HIGH
Local
- - Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. CWE-416
 Use After Free
CVE-2026-45476 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
4450 7.8 HIGH
Local
- - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CWE-122
Heap-based Buffer Overflow
CVE-2026-45475 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm