Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 6:13 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3501 8.8 重要
Network
Anthropic PBC Claude Code Anthropic PBCのClaude Codeにおける複数の脆弱性 CWE-20
CWE-77
CWE-noinfo
CVE-2026-40068 2026-05-14 10:19 2026-05-5 Show GitHub Exploit DB Packet Storm
3502 7.5 重要
Network
OpenMRS OpenMRS OpenMRSにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40075 2026-05-14 10:19 2026-05-5 Show GitHub Exploit DB Packet Storm
3503 7.8 重要
Local
デル Dell ObjectScale
elastic cloud storage
デルのelastic cloud storage等の複数製品におけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2026-40636 2026-05-14 10:19 2026-05-11 Show GitHub Exploit DB Packet Storm
3504 6.7 警告
Local
デル insightiq デルのinsightiqにおける不要な特権による実行に関する脆弱性 CWE-250
不要な特権による実行
CVE-2026-40638 2026-05-14 10:19 2026-05-12 Show GitHub Exploit DB Packet Storm
3505 7.5 重要
Network
VMware Spring Cloud Config VMwareのSpring Cloud Configにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-40981 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
3506 9.1 緊急
Network
VMware Spring Cloud Config VMwareのSpring Cloud Configにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40982 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
3507 8.1 重要
Network
VMware Spring Cloud Config VMwareのSpring Cloud ConfigにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41002 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
3508 4.4 警告
Local
VMware Spring Cloud Config VMwareのSpring Cloud Configにおけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2026-41004 2026-05-14 10:19 2026-05-7 Show GitHub Exploit DB Packet Storm
3509 5.3 警告
Network
Sync-in Sync-in Server Sync-inのSync-in Serverにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-41161 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
3510 5.3 警告
Network
angular angular angularにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41423 2026-05-14 10:19 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306291 - videolan vlc_media_player Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (applicati… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2588 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306292 - joomla joomla\! Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as dem… CWE-79
Cross-site Scripting
CVE-2011-2509 2024-11-21 10:28 2011-07-28 Show GitHub Exploit DB Packet Storm
306293 - videolan vlc_media_player Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (app… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2587 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306294 - nrl opie opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already … CWE-20
 Improper Input Validation 
CVE-2011-2490 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306295 - nrl opie Multiple off-by-one errors in opiesu.c in opiesu in OPIE 2.4.1-test1 and earlier might allow local users to gain privileges via a crafted command line. CWE-189
Numeric Errors
CVE-2011-2489 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306296 - likewise likewise_open SQL injection vulnerability in lsassd in Lsass in the Likewise Security Authority in Likewise Open 5.4 through 6.1, and Likewise Enterprise 6.0, allows local users to execute arbitrary SQL commands v… CWE-89
SQL Injection
CVE-2011-2467 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306297 - libreoffice libreoffice Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2685 2024-11-21 10:28 2011-07-22 Show GitHub Exploit DB Packet Storm
306298 7.8 HIGH
Local
redhat
fedoraproject
system-config-firewall
fedora
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privil… CWE-502
 Deserialization of Untrusted Data
CVE-2011-2520 2024-11-21 10:28 2011-07-22 Show GitHub Exploit DB Packet Storm
306299 - chyrp chyrp Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability t… CWE-22
Path Traversal
CVE-2011-2780 2024-11-21 10:28 2011-07-20 Show GitHub Exploit DB Packet Storm
306300 - hp arcsight_c5400_appliance
arcsight_c5200_appliance
arcsight_c3200_appliance
arcsight_c3400_appliance
arcsight_c1300_appliance
arcsight_c1000_appliance
windows_event_log_smartconnector
Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2779 2024-11-21 10:28 2011-07-20 Show GitHub Exploit DB Packet Storm