Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3711 7.1 重要
Adjacent
Linux Foundation automotive grade linux Linux FoundationのAutomotive Grade Linuxにおけるバッファオーバーリードの脆弱性 CWE-126
バッファオーバーリード
CVE-2026-37532 2026-05-18 11:23 2026-05-1 Show GitHub Exploit DB Packet Storm
3712 8.8 重要
Network
マイクロソフト Microsoft Data Formulator Microsoft Data Formulator のリモートでコードが実行される脆弱性 CWE-94
コード・インジェクション
CVE-2026-41094 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3713 9.1 緊急
Network
マイクロソフト Microsoft Confluence SAML SSO plugin
Microsoft JIRA SAML SSO plugin
Jira と Confluence 用の Microsoft SSO プラグインの特権昇格の脆弱性 CWE-303
CWE-Other
CVE-2026-41103 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3714 5.9 警告
Network
opentelemetry OpenTelemetry.Resources.Azure opentelemetryのOpenTelemetry.Resources.Azureにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41483 2026-05-18 11:22 2026-05-6 Show GitHub Exploit DB Packet Storm
3715 5.9 警告
Network
opentelemetry OpenTelemetry.Exporter.OneCollector opentelemetryのOpenTelemetry.Exporter.OneCollectorにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41484 2026-05-18 11:22 2026-05-6 Show GitHub Exploit DB Packet Storm
3716 5.5 警告
Local
マイクロソフト Visual Studio Code - Live Preview extension マイクロソフトのVisual Studio Code - Live Preview extensionにおける複数の脆弱性 CWE-22
CWE-22
CWE-23
CVE-2026-41612 2026-05-18 11:22 2026-05-12 Show GitHub Exploit DB Packet Storm
3717 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-43903 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3718 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-43904 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3719 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-43905 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
3720 7.8 重要
Local
OpenImageIO (OIIO) OpenImageIO (OIIO) OpenImageIO (OIIO)におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-43906 2026-05-18 11:22 2026-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2971 8.2 HIGH
Network
- - Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject … CWE-89
SQL Injection
CVE-2019-25728 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2972 9.8 CRITICAL
Network
- - PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie paramete… CWE-352
 Origin Validation Error
CVE-2019-25729 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2973 8.2 HIGH
Network
- - Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can s… CWE-89
SQL Injection
CVE-2019-25730 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2974 8.2 HIGH
Network
- - PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers… CWE-89
SQL Injection
CVE-2019-25732 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2975 8.4 HIGH
Local
- - NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a… CWE-120
Classic Buffer Overflow
CVE-2019-25733 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2976 4.0 MEDIUM
Local
- - Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanit… CWE-22
Path Traversal
CVE-2019-25734 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2977 8.4 HIGH
Local
- - AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Att… CWE-120
Classic Buffer Overflow
CVE-2019-25735 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2978 8.4 HIGH
Local
- - LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a… CWE-120
Classic Buffer Overflow
CVE-2019-25736 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2979 9.8 CRITICAL
Network
- - WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option actio… CWE-306
Missing Authentication for Critical Function
CVE-2019-25738 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
2980 6.5 MEDIUM
Network
- - Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requ… CWE-22
Path Traversal
CVE-2019-25740 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm