Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3581 7.5 重要
Network
Absinthe-graphql Absinthe Absinthe-graphqlのAbsintheにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-43967 2026-05-28 14:32 2026-05-8 Show GitHub Exploit DB Packet Storm
3582 6.1 警告
Network
The Kyverno Authors Policy-reporter-ui The Kyverno AuthorsのPolicy-reporter-uiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44245 2026-05-28 14:32 2026-05-12 Show GitHub Exploit DB Packet Storm
3583 8.6 重要
Network
Marginal v1-core Marginalのv1-coreにおける数値型間の変換の誤りに関する脆弱性 CWE-681
数値型間の変換の誤り
CVE-2026-4931 2026-05-28 14:32 2026-04-7 Show GitHub Exploit DB Packet Storm
3584 7.4 重要
Network
Project Jupyter Jupyter Server Jupyter Serverにおけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2025-61669 2026-05-28 12:05 2026-05-28 Show GitHub Exploit DB Packet Storm
3585 - - 日立 Hitachi Application Server
uCosminexus Application Runtime with Java for Apache Tomcat
uCosminexus Application Runtime with Java…
Cosminexusにおける複数の脆弱性 - CVE-2026-22007
CVE-2026-22013
CVE-2026-22016
CVE-2026-22018
CVE-2026-22021
CVE-2026-23865
CVE-2026-34268
CVE-2026-34282
2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
3586 - - 日立 Hitachi Automation Director
Hitachi Replication Manager
Hitachi Configuration Manager
Hitachi Ops Center API Configuration Manager
H…
Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品における複数の脆弱性 - CVE-2026-22007
CVE-2026-22013
CVE-2026-22016
CVE-2026-22018
CVE-2026-22021
CVE-2026-23865
CVE-2026-34268
CVE-2026-34282
2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
3587 - - 日立 Hitachi Infrastructure Analytics Advisor
Hitachi Ops Center Analyzer
Hitachi Ops Center Analyzer viewpoint
Hitachi Infrastructure Analytics Advisor,Hitachi Ops Center AnalyzerおよびHitachi Ops Center Analyzer viewpointにおける脆弱性 - CVE-2026-3314 2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
3588 - - LMSYS Org SGLang SGLangにおける複数の脆弱性 - CVE-2026-5760
CVE-2026-7301
CVE-2026-7302
CVE-2026-7304
2026-05-27 12:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3589 - - dnsmasq dnsmasq dnsmasqにおける複数の脆弱性 - CVE-2026-2291
CVE-2026-4890
CVE-2026-4891
CVE-2026-4892
CVE-2026-4893
CVE-2026-5172
2026-05-27 12:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3590 - - Linux Linux Kernel Linuxカーネルにおける複数の脆弱性 - CVE-2026-31431
CVE-2026-43284
CVE-2026-43500
2026-05-26 14:07 2026-05-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
305891 - dell kace_k2000_systems_deployment_appliance Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTM… CWE-79
Cross-site Scripting
CVE-2011-4436 2024-11-21 10:32 2011-11-12 Show GitHub Exploit DB Packet Storm
305892 - ibm db2_tools_for_z\/os The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers … CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4435 2024-11-21 10:32 2011-11-12 Show GitHub Exploit DB Packet Storm
305893 - microsoft windows_server_2008
windows_7
Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) … CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4434 2024-11-21 10:32 2011-11-12 Show GitHub Exploit DB Packet Storm
305894 - merethis centreon www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent at… CWE-310
Cryptographic Issues
CVE-2011-4432 2024-11-21 10:32 2011-11-10 Show GitHub Exploit DB Packet Storm
305895 - merethis centreon Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter. CWE-22
Path Traversal
CVE-2011-4431 2024-11-21 10:32 2011-11-10 Show GitHub Exploit DB Packet Storm
305896 - apache http_server The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of envi… CWE-20
 Improper Input Validation 
CVE-2011-4415 2024-11-21 10:32 2011-11-8 Show GitHub Exploit DB Packet Storm
305897 - courseforum projectforum Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on … CWE-79
Cross-site Scripting
CVE-2011-4277 2024-11-21 10:32 2011-11-4 Show GitHub Exploit DB Packet Storm
305898 - ark-web a-form_pc
a-form_pc_mobile
Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a … CWE-79
Cross-site Scripting
CVE-2011-4274 2024-11-21 10:32 2011-11-3 Show GitHub Exploit DB Packet Storm
305899 - goahead goahead_webserver Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to … CWE-79
Cross-site Scripting
CVE-2011-4273 2024-11-21 10:32 2011-11-3 Show GitHub Exploit DB Packet Storm
305900 - investintech absolute_pdf_server Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF documen… NVD-CWE-noinfo
CVE-2011-4223 2024-11-21 10:32 2011-11-2 Show GitHub Exploit DB Packet Storm