Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
21 5.3 警告
Network
VMware Spring Framework VMwareのSpring Frameworkにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-41852 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
22 5.1 警告
Local
ImageMagick ImageMagick ImageMagickにおける複数の脆弱性 New CWE-125
CWE-191
CVE-2026-42326 2026-06-12 14:53 2026-06-10 Show GitHub Exploit DB Packet Storm
23 7.5 重要
Network
Svelte project Svelte Svelte projectのSvelteにおける非効率的な正規表現の複雑さに関する脆弱性 New CWE-1333
非効率的な正規表現の複雑さ
CVE-2026-42567 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
24 7.5 重要
Network
Svelte project devalue Svelte projectのdevalueにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42570 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
25 6.1 警告
Network
Svelte project Svelte Svelte projectのSvelteにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42573 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
26 6.1 警告
Network
Svelte project Svelte Svelte projectのSvelteにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42599 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
27 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Windows 管理者保護のセキュリティ機能バイパスの脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-42829 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
28 7 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows Function Discovery Service (fdwsd.dll) の特権昇格の脆弱性 New CWE-362
CWE-416
CVE-2026-42836 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
29 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11 26h1
Microsoft …
Windows Projected File System の特権の昇格の脆弱性 New CWE-125
境界外読み取り
CVE-2026-42837 2026-06-12 14:53 2026-06-9 Show GitHub Exploit DB Packet Storm
30 9.6 緊急
Network
flowiseai flowise flowiseaiのflowiseにおける複数の脆弱性 New CWE-284
CWE-639
CWE-915
CVE-2026-42861 2026-06-12 14:52 2026-06-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2181 6.5 MEDIUM
Network
google chrome Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) CWE-200
Information Exposure
CVE-2026-11203 2026-06-6 10:36 2026-06-5 Show GitHub Exploit DB Packet Storm
2182 6.5 MEDIUM
Network
gkostka lwext4 An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 files… CWE-125
Out-of-bounds Read
CVE-2025-70101 2026-06-6 06:10 2026-06-3 Show GitHub Exploit DB Packet Storm
2183 5.5 MEDIUM
Local
gkostka lwext4 A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 fi… CWE-369
 Divide By Zero
CVE-2025-70100 2026-06-6 06:09 2026-06-3 Show GitHub Exploit DB Packet Storm
2184 9.8 CRITICAL
Network
freedesktop libinput In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution CWE-93
CRLF Injection
CVE-2026-50292 2026-06-6 06:06 2026-06-5 Show GitHub Exploit DB Packet Storm
2185 9.1 CRITICAL
Network
netty netty-incubator-codec-ohttp The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2026-48040 2026-06-6 06:04 2026-06-5 Show GitHub Exploit DB Packet Storm
2186 5.3 MEDIUM
Network
netty netty-incubator-codec-ohttp The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distin… CWE-330
 Use of Insufficiently Random Values
CVE-2026-41207 2026-06-6 06:01 2026-06-5 Show GitHub Exploit DB Packet Storm
2187 - - - A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network a… CWE-22
CWE-798
Path Traversal
 Use of Hard-coded Credentials
CVE-2026-11414 2026-06-6 05:49 2026-06-6 Show GitHub Exploit DB Packet Storm
2188 - - - A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authen… CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-11419 2026-06-6 05:49 2026-06-6 Show GitHub Exploit DB Packet Storm
2189 - - - Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on… CWE-22
CWE-306
Path Traversal
Missing Authentication for Critical Function
CVE-2026-11420 2026-06-6 05:49 2026-06-6 Show GitHub Exploit DB Packet Storm
2190 8.0 HIGH
Network
- - An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges t… CWE-426
 Untrusted Search Path
CVE-2026-11400 2026-06-6 05:49 2026-06-6 Show GitHub Exploit DB Packet Storm