Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 6:13 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217831 6.8 警告 Xavoc Technocrats Pvt. Ltd. - Xavoc Technocrats xEpan CMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-8429 2014-12-1 18:04 2014-10-22 Show GitHub Exploit DB Packet Storm
217832 4.3 警告 レッドハット - FreeIPA の Web UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7850 2014-12-1 17:37 2014-11-18 Show GitHub Exploit DB Packet Storm
217833 9.3 危険 Enalean - Enalean Tuleap における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-7178 2014-12-1 17:33 2014-09-18 Show GitHub Exploit DB Packet Storm
217834 5 警告 MatrikonOPC - DNP3 用 MatrikonOPC OPC Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-5426 2014-12-1 17:24 2014-10-22 Show GitHub Exploit DB Packet Storm
217835 6.8 警告 OpenVPN Technologies - OpenVPN Access Server のデスクトップクライアントの XML-RPC API におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9104 2014-12-1 17:22 2014-07-1 Show GitHub Exploit DB Packet Storm
217836 6.8 警告 Oxwall
skalfa
- Oxwall および SkaDate Lite におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9101 2014-12-1 17:21 2014-07-28 Show GitHub Exploit DB Packet Storm
217837 10 危険 ARRIS Group - ARRIS VAP2500 の管理ポータルにおける任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2014-8423 2014-12-1 17:02 2014-11-25 Show GitHub Exploit DB Packet Storm
217838 7.8 危険 ARRIS Group - ARRIS VAP2500 における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2014-8424 2014-12-1 17:01 2014-11-25 Show GitHub Exploit DB Packet Storm
217839 7.8 危険 ARRIS Group - ARRIS VAP2500 の管理ポータルにおける資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-8425 2014-12-1 17:00 2014-11-25 Show GitHub Exploit DB Packet Storm
217840 5 警告 IBM - 複数の IBM Security QRadar 製品における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-6075 2014-12-1 16:46 2014-11-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1291 9.8 CRITICAL
Network
termix termix Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tu… Update CWE-78
OS Command 
CVE-2026-45748 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
1292 8.1 HIGH
Network
termix termix Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the request… Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45743 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
1293 6.5 MEDIUM
Network
- - IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required fo… Update CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-42539 2026-06-9 02:16 2026-06-5 Show GitHub Exploit DB Packet Storm
1294 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cau… Update CWE-121
Stack-based Buffer Overflow
CVE-2026-36785 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
1295 9.1 CRITICAL
Network
- - An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. Update CWE-22
Path Traversal
CVE-2026-36500 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
1296 4.8 MEDIUM
Network
- - Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads i… Update CWE-79
Cross-site Scripting
CVE-2026-36460 2026-06-9 02:16 2026-06-4 Show GitHub Exploit DB Packet Storm
1297 5.3 MEDIUM
Network
libxls_project libxls A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory origi… Update CWE-908
 Use of Uninitialized Resource
CVE-2026-26825 2026-06-9 02:16 2026-06-4 Show GitHub Exploit DB Packet Storm
1298 7.3 HIGH
Network
- - A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir… Update CWE-74
CWE-77
Injection
Command Injection
CVE-2026-11451 2026-06-9 02:16 2026-06-7 Show GitHub Exploit DB Packet Storm
1299 8.1 HIGH
Network
- - MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured down… Update CWE-22
Path Traversal
CVE-2026-11416 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
1300 2.4 LOW
Network
- - A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of t… Update CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-11338 2026-06-9 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm