Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 2:12 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3221 4.6 警告
Network
- OpenC3のOpenC3 COSMOSにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42086 2026-05-11 11:09 2026-05-4 Show GitHub Exploit DB Packet Storm
3222 9.6 緊急
Network
- OpenC3のOpenC3 COSMOSにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-42087 2026-05-11 11:09 2026-05-4 Show GitHub Exploit DB Packet Storm
3223 9.8 緊急
Network
litellm litellm LiteLLMにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-42208 2026-05-11 11:09 2026-05-8 Show GitHub Exploit DB Packet Storm
3224 9.1 緊急
Network
OpenEXR OpenEXR OpenEXRにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-42216 2026-05-11 11:09 2026-05-7 Show GitHub Exploit DB Packet Storm
3225 9.8 緊急
Network
OpenEXR OpenEXR OpenEXRにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-42217 2026-05-11 11:09 2026-05-7 Show GitHub Exploit DB Packet Storm
3226 8.8 重要
Network
litellm litellm LiteLLMにおける複数の脆弱性 CWE-77
CWE-78
CVE-2026-42271 2026-05-11 11:09 2026-05-8 Show GitHub Exploit DB Packet Storm
3227 8.7 重要
Network
NetFoundry zrok NetFoundryのzrokにおける複数の脆弱性 CWE-22
CWE-61
CVE-2026-42275 2026-05-11 11:09 2026-05-8 Show GitHub Exploit DB Packet Storm
3228 5.8 警告
Network
solidtime solidtime solidtimeにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-42279 2026-05-11 11:09 2026-05-8 Show GitHub Exploit DB Packet Storm
3229 7.5 重要
Network
マイクロソフト Azure DevOps Azure DevOps Information Disclosure Vulnerability CWE-200
情報漏えい
CVE-2026-42826 2026-05-11 11:09 2026-05-7 Show GitHub Exploit DB Packet Storm
3230 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-43017 2026-05-11 11:08 2026-05-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306671 - microsoft jscript
vbscript
Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka… CWE-189
Numeric Errors
CVE-2011-0663 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306672 - microsoft windows_server_2008
windows_xp
windows_7
windows_vista
windows_server_2003
windows_2003_server
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R… CWE-399
 Resource Management Errors
CVE-2011-0662 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306673 - microsoft windows_server_2008
windows_xp
windows_7
windows_vista
windows_server_2003
windows_2003_server
The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not prop… CWE-20
 Improper Input Validation 
CVE-2011-0661 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306674 - microsoft windows_7
windows_xp
windows_server_2003
windows_2003_server
windows_server_2008
windows_vista
The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB ser… CWE-20
 Improper Input Validation 
CVE-2011-0660 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306675 - microsoft windows_server_2008
windows_xp
windows_7
windows_vista
windows_server_2003
windows_2003_server
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does no… CWE-20
 Improper Input Validation 
CVE-2011-0657 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306676 - microsoft open_xml_file_format_converter
office
powerpoint
powerpoint_web_app
office_compatibility_pack
powerpoint_viewer
office_powerpoint_viewer
Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 200… CWE-20
 Improper Input Validation 
CVE-2011-0656 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306677 - microsoft open_xml_file_format_converter
office
powerpoint
powerpoint_web_app
office_compatibility_pack
powerpoint_viewer
office_powerpoint_viewer
Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; P… CWE-20
 Improper Input Validation 
CVE-2011-0655 2024-11-21 10:24 2011-04-14 Show GitHub Exploit DB Packet Storm
306678 - tincan phplist Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit admini… CWE-352
 Origin Validation Error
CVE-2011-0748 2024-11-21 10:24 2011-04-13 Show GitHub Exploit DB Packet Storm
306679 - zyxel o2_dsl_router_classic Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests t… CWE-352
 Origin Validation Error
CVE-2011-0746 2024-11-21 10:24 2011-04-13 Show GitHub Exploit DB Packet Storm
306680 - pwhois layer_four_traceroute Unspecified vulnerability in lft in pWhois Layer Four Traceroute (LFT) 3.x before 3.3 allows local users to gain privileges via a crafted command line. NVD-CWE-noinfo
CVE-2011-0765 2024-11-21 10:24 2011-04-10 Show GitHub Exploit DB Packet Storm