Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2931 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるHTTPS セッション内の Secure 属性がない重要な Cookie に関する脆弱性 CWE-614
HTTPS セッション内の Secure 属性がない重要な Cookie
CVE-2025-52608 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2932 5.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2025-52609 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2933 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52611 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2934 8.8 重要
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2025-52612 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2935 7.5 重要
Network
Open JS Foundation Node Version Manager (NVM) Open JS FoundationのNode Version Manager (NVM)におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-10796 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2936 7.8 重要
Local
NVIDIA transformers4rec NVIDIAのtransformers4recにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24162 2026-06-8 11:49 2026-05-26 Show GitHub Exploit DB Packet Storm
2937 7.8 重要
Local
NVIDIA NVTabular NVIDIAのNVTabularにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24221 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
2938 7.8 重要
Local
NVIDIA NVTabular NVIDIAのNVTabularにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24237 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
2939 6.8 警告
Network
SWUpdate SWUpdate SWUpdateにおける複数の脆弱性 CWE-125
CWE-191
CVE-2026-28525 2026-06-8 11:49 2026-04-23 Show GitHub Exploit DB Packet Storm
2940 7.5 重要
Network
turbo-stream
Shopify
React Router
Turbo Stream
Shopify等の複数ベンダの製品における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-34077 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
681 5.3 MEDIUM
Network
- - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete an… New CWE-862
 Missing Authorization
CVE-2026-54029 2026-06-26 03:58 2026-06-26 Show GitHub Exploit DB Packet Storm
682 - - - pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. In the reproduced case… New CWE-200
CWE-522
Information Exposure
 Insufficiently Protected Credentials
CVE-2026-50017 2026-06-26 03:58 2026-06-26 Show GitHub Exploit DB Packet Storm
683 9.9 CRITICAL
Network
microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. New CWE-284
Improper Access Control
CVE-2026-47647 2026-06-26 03:57 2026-06-19 Show GitHub Exploit DB Packet Storm
684 - - - motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path travers… New CWE-22
Path Traversal
CVE-2026-55488 2026-06-26 03:56 2026-06-25 Show GitHub Exploit DB Packet Storm
685 4.3 MEDIUM
Network
- - AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept a… New CWE-22
Path Traversal
CVE-2026-48789 2026-06-26 03:56 2026-06-25 Show GitHub Exploit DB Packet Storm
686 0.0 NONE
Network
- - AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files re… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-55611 2026-06-26 03:56 2026-06-25 Show GitHub Exploit DB Packet Storm
687 5.5 MEDIUM
Local
- - motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with… New CWE-200
CWE-522
CWE-732
Information Exposure
 Insufficiently Protected Credentials
 Incorrect Permission Assignment for Critical Resource
CVE-2026-32315 2026-06-26 03:56 2026-06-25 Show GitHub Exploit DB Packet Storm
688 7.1 HIGH
Network
silabs emberznet In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages … New CWE-787
 Out-of-bounds Write
CVE-2026-47151 2026-06-26 03:51 2026-06-25 Show GitHub Exploit DB Packet Storm
689 7.1 HIGH
Network
silabs emberznet In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These… New CWE-787
 Out-of-bounds Write
CVE-2026-47150 2026-06-26 03:49 2026-06-25 Show GitHub Exploit DB Packet Storm
690 6.5 MEDIUM
Network
silabs emberznet In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has … New CWE-125
Out-of-bounds Read
CVE-2026-47149 2026-06-26 03:48 2026-06-25 Show GitHub Exploit DB Packet Storm