Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3351 7.5 重要
Network
日本エイサー Acer Connect M6E 5G Firmware エイサーのAcer Connect M6E 5G Firmwareにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-50210 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3352 9.8 緊急
Network
日本エイサー Acer Connect M6E 5G Firmware エイサーのAcer Connect M6E 5G Firmwareにおける書式文字列に関する脆弱性 CWE-134
書式文字列の問題
CVE-2026-50211 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3353 6.5 警告
Adjacent
日本エイサー Acer Connect M6E 5G Firmware エイサーのAcer Connect M6E 5G Firmwareにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-50212 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3354 7.5 重要
Network
日本エイサー Acer Connect M6E 5G Firmware エイサーのAcer Connect M6E 5G Firmwareにおけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2026-50213 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3355 5.5 警告
Local
日本エイサー Care Center エイサーのCare Centerにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-9490 2026-06-8 11:49 2026-05-25 Show GitHub Exploit DB Packet Storm
3356 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52606 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3357 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるHTTPS セッション内の Secure 属性がない重要な Cookie に関する脆弱性 CWE-614
HTTPS セッション内の Secure 属性がない重要な Cookie
CVE-2025-52608 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3358 5.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2025-52609 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3359 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52611 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
3360 8.8 重要
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2025-52612 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
591 6.5 MEDIUM
Network
envoyproxy envoy Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC m… Update CWE-416
 Use After Free
CVE-2026-47207 2026-06-28 05:20 2026-06-27 Show GitHub Exploit DB Packet Storm
592 7.5 HIGH
Network
envoyproxy envoy Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vul… Update CWE-476
 NULL Pointer Dereference
CVE-2026-47221 2026-06-28 05:17 2026-06-27 Show GitHub Exploit DB Packet Storm
593 4.3 MEDIUM
Adjacent
envoyproxy envoy Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the … Update CWE-130
 Improper Handling of Length Parameter Inconsistency
CVE-2026-47692 2026-06-28 05:09 2026-06-27 Show GitHub Exploit DB Packet Storm
594 5.3 MEDIUM
Network
wolfssl wolfssl The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier… Update CWE-120
CWE-787
Classic Buffer Overflow
 Out-of-bounds Write
CVE-2026-6681 2026-06-28 05:02 2026-06-26 Show GitHub Exploit DB Packet Storm
595 7.5 HIGH
Network
wolfssl wolfssl X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted. Update CWE-295
Improper Certificate Validation 
CVE-2026-6731 2026-06-28 05:02 2026-06-26 Show GitHub Exploit DB Packet Storm
596 5.3 MEDIUM
Network
wolfssl wolfssl OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status o… Update CWE-295
Improper Certificate Validation 
CVE-2026-10098 2026-06-28 05:01 2026-06-26 Show GitHub Exploit DB Packet Storm
597 7.5 HIGH
Network
wolfssl wolfssl Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI… Update CWE-287
NVD-CWE-noinfo
Improper Authentication
CVE-2026-11703 2026-06-28 04:59 2026-06-26 Show GitHub Exploit DB Packet Storm
598 6.5 MEDIUM
Network
wolfssl wolfssl TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth e… Update CWE-287
NVD-CWE-noinfo
Improper Authentication
CVE-2026-55962 2026-06-28 04:57 2026-06-26 Show GitHub Exploit DB Packet Storm
599 5.3 MEDIUM
Network
wolfssl wolfssl When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC. Update CWE-757
Algorithm Downgrade
CVE-2026-6092 2026-06-28 04:55 2026-06-26 Show GitHub Exploit DB Packet Storm
600 7.5 HIGH
Network
wolfssl wolfssl Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer. Update CWE-787
 Out-of-bounds Write
CVE-2026-6325 2026-06-28 04:51 2026-06-26 Show GitHub Exploit DB Packet Storm