Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3921 9.8 緊急
Network
libexpat project libexpat libexpat projectのlibexpatにおけるエントロピー不足に関する脆弱性 CWE-331
エントロピー不足
CVE-2026-7210 2026-05-18 11:24 2026-05-11 Show GitHub Exploit DB Packet Storm
3922 8.8 重要
Adjacent
ZyXEL WRE6505 ファームウェア ZyXELのWRE6505 ファームウェアにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-7256 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
3923 4.4 警告
Local
ZyXEL WRE6505 ファームウェア ZyXELのWRE6505 ファームウェアにおける重要な情報のセキュアでない格納に関する脆弱性 CWE-922
重要な情報のセキュアでない格納
CVE-2026-7257 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
3924 7.5 重要
Network
ZyXEL NWA1100-N ファームウェア ZyXELのNWA1100-N ファームウェアにおける古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-7287 2026-05-18 11:24 2026-05-12 Show GitHub Exploit DB Packet Storm
3925 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-7377 2026-05-18 11:24 2026-05-14 Show GitHub Exploit DB Packet Storm
3926 9.8 緊急
Network
OpenClaw OpenClaw OpenClawにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-8305 2026-05-18 11:23 2026-05-11 Show GitHub Exploit DB Packet Storm
3927 9.8 緊急
Network
Mozilla Foundation Mozilla Firefox Mozilla FoundationのMozilla Firefoxにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-8401 2026-05-18 11:23 2026-05-12 Show GitHub Exploit DB Packet Storm
3928 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-8581 2026-05-18 11:23 2026-05-14 Show GitHub Exploit DB Packet Storm
3929 4.3 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるアセットへのアクセス後に実装されたアクセス制御チェックに関する脆弱性 CWE-1280
アセットへのアクセス後に実装されたアクセス制御チェック
CVE-2026-3607 2026-05-18 11:23 2026-05-14 Show GitHub Exploit DB Packet Storm
3930 9.8 緊急
Network
フォーティネット FortiSandbox
FortiSandbox PaaS
FortiSandbox Cloud
フォーティネットのFortiSandbox等の複数製品における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-26083 2026-05-18 11:23 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306091 - indusoft web_studio Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x1… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-4052 2024-11-21 10:31 2011-12-5 Show GitHub Exploit DB Packet Storm
306092 - indusoft web_studio CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vecto… CWE-287
Improper Authentication
CVE-2011-4051 2024-11-21 10:31 2011-12-5 Show GitHub Exploit DB Packet Storm
306093 - schneider-electric vijeo_historian
citecthistorian
citectscada_reports
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arb… CWE-22
Path Traversal
CVE-2011-4036 2024-11-21 10:31 2011-12-2 Show GitHub Exploit DB Packet Storm
306094 - schneider-electric vijeo_historian
citecthistorian
citectscada_reports
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to i… CWE-79
Cross-site Scripting
CVE-2011-4035 2024-11-21 10:31 2011-12-2 Show GitHub Exploit DB Packet Storm
306095 - schneider-electric vijeo_historian
citecthistorian
citectscada_reports
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allo… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-4034 2024-11-21 10:31 2011-12-2 Show GitHub Exploit DB Packet Storm
306096 - schneider-electric vijeo_historian
citecthistorian
citectscada_reports
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allo… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-4033 2024-11-21 10:31 2011-12-2 Show GitHub Exploit DB Packet Storm
306097 - hp color_laserjet_enterprise_cp4520
laserjet_m5035
laserjet_enterprise_600
laserjet_4250
color_laserjet_cp3505
color_laserjet_4730
color_laserjet_enterprise_cp4525
laserjet_p3005
The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, … CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4161 2024-11-21 10:31 2011-12-2 Show GitHub Exploit DB Packet Storm
306098 - mawashimono nikki Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors. CWE-22
Path Traversal
CVE-2011-4001 2024-11-21 10:31 2011-12-1 Show GitHub Exploit DB Packet Storm
306099 - mawashimono nikki HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." CWE-78
OS Command 
CVE-2011-4002 2024-11-21 10:31 2011-11-30 Show GitHub Exploit DB Packet Storm
306100 - sunplus-tech dvr_remote_activex_control DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server. CWE-94
Code Injection
CVE-2011-3828 2024-11-21 10:31 2011-11-26 Show GitHub Exploit DB Packet Storm