Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3421 7.5 重要
Network
マイクロソフト Microsoft 365 Copilot BizChat M365 Copilot の情報漏えいの脆弱性 CWE-74
インジェクション
CVE-2026-26164 2026-05-11 11:12 2026-05-7 Show GitHub Exploit DB Packet Storm
3422 9.8 緊急
Network
vm2 project vm2 vm2 projectのvm2における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-26956 2026-05-11 11:12 2026-05-4 Show GitHub Exploit DB Packet Storm
3423 6.5 警告
Network
Traccar Ltd Traccar Traccar LtdのTraccarにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2026-27644 2026-05-11 11:12 2026-05-5 Show GitHub Exploit DB Packet Storm
3424 5.4 警告
Network
Traccar Ltd Traccar Traccar LtdのTraccarにおけるブラインド XPath インジェクションの脆弱性 CWE-91
ブラインド XPath インジェクション
CVE-2026-27693 2026-05-11 11:12 2026-05-5 Show GitHub Exploit DB Packet Storm
3425 5.4 警告
Network
Traccar Ltd Traccar Traccar LtdのTraccarにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-27694 2026-05-11 11:11 2026-05-5 Show GitHub Exploit DB Packet Storm
3426 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-31753 2026-05-11 11:11 2026-05-1 Show GitHub Exploit DB Packet Storm
3427 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-31754 2026-05-11 11:11 2026-05-1 Show GitHub Exploit DB Packet Storm
3428 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-31755 2026-05-11 11:11 2026-05-1 Show GitHub Exploit DB Packet Storm
3429 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-31756 2026-05-11 11:11 2026-05-1 Show GitHub Exploit DB Packet Storm
3430 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2026-31757 2026-05-11 11:11 2026-05-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306361 6.1 MEDIUM
Network
bbpress bbpress bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. CWE-79
Cross-site Scripting
CVE-2011-1150 2024-11-21 10:25 2020-02-6 Show GitHub Exploit DB Packet Storm
306362 6.1 MEDIUM
Network
phpshop phpshop PHPShop through 0.8.1 has XSS. CWE-79
Cross-site Scripting
CVE-2011-1069 2024-11-21 10:25 2020-02-6 Show GitHub Exploit DB Packet Storm
306363 6.1 MEDIUM
Network
vanillaforums vanilla Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. CWE-79
Cross-site Scripting
CVE-2011-1009 2024-11-21 10:25 2020-02-6 Show GitHub Exploit DB Packet Storm
306364 9.8 CRITICAL
Network
smarty
debian
smarty
debian_linux
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. CWE-20
 Improper Input Validation 
CVE-2011-1028 2024-11-21 10:25 2019-11-21 Show GitHub Exploit DB Packet Storm
306365 7.8 HIGH
Local
unixodbc
debian
opensuse
redhat
unixodbc
debian_linux
opensuse
enterprise_linux
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. CWE-120
Classic Buffer Overflow
CVE-2011-1145 2024-11-21 10:25 2019-11-14 Show GitHub Exploit DB Packet Storm
306366 4.7 MEDIUM
Local
tesseract_project
debian
tesseract
debian_linux
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file. CWE-59
Link Following
CVE-2011-1136 2024-11-21 10:25 2019-11-14 Show GitHub Exploit DB Packet Storm
306367 7.8 HIGH
Local
v86d_project
debian
v86d
debian_linux
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences. CWE-863
 Incorrect Authorization
CVE-2011-1070 2024-11-21 10:25 2019-11-14 Show GitHub Exploit DB Packet Storm
306368 6.1 MEDIUM
Network
s9y serendipity Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/Imag… CWE-79
Cross-site Scripting
CVE-2011-1135 2024-11-21 10:25 2019-11-6 Show GitHub Exploit DB Packet Storm
306369 9.8 CRITICAL
Network
s9y serendipity Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2011-1134 2024-11-21 10:25 2019-11-6 Show GitHub Exploit DB Packet Storm
306370 6.1 MEDIUM
Network
s9y serendipity Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php. CWE-79
Cross-site Scripting
CVE-2011-1133 2024-11-21 10:25 2019-11-6 Show GitHub Exploit DB Packet Storm