Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
221521 5 警告 PaperThin - PaperThin CommonSpot におけるディレクトリ一覧から重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-2872 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221522 6.5 警告 PaperThin - PaperThin CommonSpot におけるアクションを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2862 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221523 5 警告 PaperThin - PaperThin CommonSpot における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-2871 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221524 4.3 警告 PaperThin - PaperThin CommonSpot におけるクロスサイトスクリプティングの脆弱性 CWE-Other
その他
CVE-2014-2861 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221525 4.3 警告 PaperThin - PaperThin CommonSpot におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2860 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221526 7.5 危険 PaperThin - PaperThin CommonSpot におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2859 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
221527 4 警告 コクヨS&T株式会社 - Android 版 CamiApp における Content Provider のアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1986 2014-04-21 18:31 2014-04-14 Show GitHub Exploit DB Packet Storm
221528 2.1 注意 PackageKit Project - PackageKit の Zypper バックエンドにおけるパッケージをダウングレードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1764 2014-04-21 18:28 2013-05-8 Show GitHub Exploit DB Packet Storm
221529 4.6 警告 bzip.org - bzip2 の bzexe コマンドにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4089 2014-04-21 17:56 2011-12-4 Show GitHub Exploit DB Packet Storm
221530 7.5 危険 Novell - SUSE Studio Onsite および SUSE Studio Extension for System z で使用される KIWI における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2011-4195 2014-04-21 17:27 2011-12-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
361 5.9 MEDIUM
Network
- - Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application … New CWE-476
 NULL Pointer Dereference
CVE-2026-42766 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
362 7.5 HIGH
Network
- - Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a … New CWE-476
 NULL Pointer Dereference
CVE-2026-42765 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
363 7.5 HIGH
Network
- - Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer … New CWE-476
 NULL Pointer Dereference
CVE-2026-42764 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
364 - - - Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verificatio… New CWE-415
 Double Free
CVE-2026-35188 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
365 7.5 HIGH
Network
- - Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platfo… New CWE-125
Out-of-bounds Read
CVE-2026-34180 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
366 - - - Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP objec… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-10721 2026-06-10 17:16 2026-06-10 Show GitHub Exploit DB Packet Storm
367 - - - A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexp… New CWE-617
 Reachable Assertion
CVE-2026-29116 2026-06-10 16:16 2026-06-10 Show GitHub Exploit DB Packet Storm
368 - - - A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpec… New CWE-617
 Reachable Assertion
CVE-2026-29115 2026-06-10 16:16 2026-06-10 Show GitHub Exploit DB Packet Storm
369 - - - A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudul… New CWE-538
 File and Directory Information Exposure
CVE-2026-29114 2026-06-10 16:16 2026-06-10 Show GitHub Exploit DB Packet Storm
370 - - - An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken … New CWE-502
 Deserialization of Untrusted Data
CVE-2026-11815 2026-06-10 16:16 2026-06-10 Show GitHub Exploit DB Packet Storm