Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223791 6.8 警告 マイクロソフト - Android 用 Microsoft Bing アプリケーションにおける任意の APK ファイルをインストールされる脆弱性 CWE-94
コード・インジェクション
CVE-2014-1670 2014-01-28 15:48 2014-01-21 Show GitHub Exploit DB Packet Storm
223792 9.3 危険 SmartBear Software - SoapUI の WSDL/WADL インポート機能における任意の Java コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-1202 2014-01-28 15:38 2014-01-14 Show GitHub Exploit DB Packet Storm
223793 4.3 警告 レッドハット - libvirt における ACL の domain:getattr および connect:search_domains の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0028 2014-01-28 10:57 2014-01-16 Show GitHub Exploit DB Packet Storm
223794 4 警告 Drupal - Drupal の Taxonomy モジュールにおける重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1476 2014-01-28 10:11 2014-01-15 Show GitHub Exploit DB Packet Storm
223795 7.5 危険 Drupal - Drupal の OpenID モジュールにおける他のユーザとして認証される脆弱性 CWE-noinfo
情報不足
CVE-2014-1475 2014-01-28 10:11 2014-01-15 Show GitHub Exploit DB Packet Storm
223796 7.5 危険 live555 - VideoLAN VLC media player で使用される Live Networks Live555 Streaming Media におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-189
CVE-2013-6934 2014-01-27 18:54 2013-12-30 Show GitHub Exploit DB Packet Storm
223797 7.5 危険 live555 - VideoLAN VLC media player で使用される Live Networks Live555 Streaming Media におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-189
CVE-2013-6933 2014-01-27 18:53 2013-12-30 Show GitHub Exploit DB Packet Storm
223798 2.1 注意 IBM - Windows 上で稼働する IBM Tivoli Storage Manager のクライアントにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-5371 2014-01-27 18:52 2013-08-22 Show GitHub Exploit DB Packet Storm
223799 4.3 警告 IBM - IBM System X および Flex System サーバの Integrated Management Module 2 における暗号保護メカニズムを回避される脆弱性 CWE-310
暗号の問題
CVE-2013-4030 2014-01-27 18:48 2013-09-10 Show GitHub Exploit DB Packet Storm
223800 7.8 危険 Thecus - Thecus NAS サーバの N8800 ファームウェアにおける重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-5669 2014-01-27 18:10 2013-08-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
561 - - - Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm… New CWE-121
Stack-based Buffer Overflow
CVE-2026-49760 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
562 - - - Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chu… New CWE-121
Stack-based Buffer Overflow
CVE-2026-49759 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
563 - - - Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/… New CWE-863
CWE-1025
 Incorrect Authorization
 Comparison Using Wrong Factors
CVE-2026-48860 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
564 - - - Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. W… New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-48859 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
565 4.3 MEDIUM
Network
google chrome Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High) New CWE-457
 Use of Uninitialized Variable
CVE-2026-11668 2026-06-11 01:17 2026-06-9 Show GitHub Exploit DB Packet Storm
566 - - - Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-48858 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
567 - - - Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request… New CWE-601
Open Redirect
CVE-2026-48856 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
568 - - - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of… New CWE-200
Information Exposure
CVE-2026-48855 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
569 5.0 MEDIUM
Network
- - OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to O… New CWE-345
CWE-668
 Insufficient Verification of Data Authenticity
 Exposure of Resource to Wrong Sphere
CVE-2026-48096 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm
570 8.3 HIGH
Network
- - Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in … New CWE-639
CWE-862
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
CVE-2026-46558 2026-06-11 01:17 2026-06-11 Show GitHub Exploit DB Packet Storm