Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4211 8.8 重要
Network
Tabby Tabby TabbyにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-45035 2026-05-21 10:55 2026-05-15 Show GitHub Exploit DB Packet Storm
4212 7 重要
Local
Tabby Tabby TabbyにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-45036 2026-05-21 10:55 2026-05-15 Show GitHub Exploit DB Packet Storm
4213 7.1 重要
Network
Tabby Tabby Tabbyにおける複数の脆弱性 CWE-184
CWE-601
CVE-2026-45037 2026-05-21 10:55 2026-05-15 Show GitHub Exploit DB Packet Storm
4214 7.8 重要
Local
Tabby Tabby Tabbyにおけるエスケープ、メタ、またはコントロールシーケンスの不適切な無効化に関する脆弱性 CWE-150
エスケープ、メタ、またはコントロールシーケンスの不適切な無効化
CVE-2026-45038 2026-05-21 10:54 2026-05-15 Show GitHub Exploit DB Packet Storm
4215 9.8 緊急
Network
Zeit, Inc. Turborepo Vercel, Inc. (旧 Zeit, Inc.)のTurborepoにおける信頼できない検索パスに関する脆弱性 CWE-426
信頼性のない検索パス
CVE-2026-45772 2026-05-21 10:54 2026-05-15 Show GitHub Exploit DB Packet Storm
4216 6.5 警告
Network
Zeit, Inc. Turborepo Vercel, Inc. (旧 Zeit, Inc.)のTurborepoにおける複数の脆弱性 CWE-352
CWE-384
CVE-2026-45773 2026-05-21 10:54 2026-05-15 Show GitHub Exploit DB Packet Storm
4217 7.8 重要
Local
Zeit, Inc. The Turborepo Language Server Protocol (LSP) Vercel, Inc. (旧 Zeit, Inc.)のThe Turborepo Language Server Protocol (LSP)におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-46508 2026-05-21 10:54 2026-05-15 Show GitHub Exploit DB Packet Storm
4218 9.1 緊急
Network
FreeRTOS coreMQTT FreeRTOSのcoreMQTTにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-8686 2026-05-21 10:54 2026-05-15 Show GitHub Exploit DB Packet Storm
4219 9.1 緊急
Network
Aden OpenHive AdenのOpenHiveにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-8757 2026-05-21 10:54 2026-05-17 Show GitHub Exploit DB Packet Storm
4220 6.5 警告
Network
Kilo Code Kilo Code Kilo Codeにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-8765 2026-05-21 10:54 2026-05-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
344771 - jetbox jetbox_cms PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter. NVD-CWE-Other
CVE-2006-2270 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
344772 - verisign i-nav The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable fi… NVD-CWE-Other
CVE-2006-2273 2018-10-19 01:38 2006-05-12 Show GitHub Exploit DB Packet Storm
344773 - apple mac_os_x Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash wh… NVD-CWE-Other
CVE-2006-2277 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344774 - arabless saphplesson SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow paramet… NVD-CWE-Other
CVE-2006-2278 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344775 - arabless saphplesson Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameter… NVD-CWE-Other
CVE-2006-2279 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344776 - openengine openengine Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template… NVD-CWE-Other
CVE-2006-2280 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344777 - x-scripts x-poll X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it. CWE-94
Code Injection
CVE-2006-2281 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344778 - x7_group x7_chat Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to … NVD-CWE-Other
CVE-2006-2282 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344779 - spiffyjr phpraid Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5 through 3.0.b3 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) auth… NVD-CWE-Other
CVE-2006-2283 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
344780 - claroline
dokeos
claroline
dokeos
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and th… NVD-CWE-Other
CVE-2006-2284 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm