Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
471 6.5 警告
Network
マイクロソフト Microsoft Graph Microsoft Graph の情報漏えいの脆弱性 New CWE-200
CWE-noinfo
CVE-2026-47655 2026-06-22 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
472 7.5 重要
Network
VMware Spring AI VMwareのSpring AIにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 New CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-47835 2026-06-22 11:49 2026-06-15 Show GitHub Exploit DB Packet Storm
473 8.1 重要
Network
VMware Spring Security VMwareのSpring Securityにおける認証に関する脆弱性 New CWE-287
不適切な認証
CVE-2026-47838 2026-06-22 11:49 2026-06-10 Show GitHub Exploit DB Packet Storm
474 7.8 重要
Local
アドビシステムズ Adobe Acrobat Reader DC
Adobe Acrobat
Adobe Acrobat DC
アドビのAdobe Acrobat等の複数製品における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2026-47965 2026-06-22 11:49 2026-06-12 Show GitHub Exploit DB Packet Storm
475 8.2 重要
Network
アドビシステムズ Adobe Acrobat アドビのAdobe Acrobatにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-48294 2026-06-22 11:49 2026-06-17 Show GitHub Exploit DB Packet Storm
476 9.3 緊急
Network
Rocket.Chat Rocket.Chat Rocket.Chatにおけるアクセス制御に関する脆弱性 New CWE-284
不適切なアクセス制御
CVE-2026-48616 2026-06-22 11:49 2026-06-17 Show GitHub Exploit DB Packet Storm
477 7.5 重要
Network
ws project ws ws projectのwsにおける複数の脆弱性 New CWE-400
CWE-770
CVE-2026-48779 2026-06-22 11:49 2026-06-17 Show GitHub Exploit DB Packet Storm
478 7.5 重要
Network
Rocket.Chat Rocket.Chat Rocket.Chatにおける認証に関する脆弱性 New CWE-287
不適切な認証
CVE-2026-48929 2026-06-22 11:49 2026-06-17 Show GitHub Exploit DB Packet Storm
479 9.8 緊急
Network
MariaDB Corporation Ab. MariaDB MariaDB Corporation Ab.のMariaDBにおけるOS コマンドインジェクションの脆弱性 New CWE-78
OSコマンド・インジェクション
CVE-2026-49261 2026-06-22 11:49 2026-06-11 Show GitHub Exploit DB Packet Storm
480 9.1 緊急
Network
Apache Software Foundation Apache Shiro Apache Software FoundationのApache ShiroにおけるLDAP インジェクションの脆弱性 New CWE-90
LDAP インジェクション
CVE-2026-49268 2026-06-22 11:48 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
257151 8.8 HIGH
Network
google
debian
chrome
debian_linux
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag… CWE-20
 Improper Input Validation 
CVE-2017-5092 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257152 8.8 HIGH
Network
google
debian
redhat
chrome
debian_linux
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. CWE-416
 Use After Free
CVE-2017-5091 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257153 6.5 MEDIUM
Network
google chrome Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name containing a U+0620 character… CWE-20
 Improper Input Validation 
CVE-2017-5090 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257154 6.5 MEDIUM
Network
google
redhat
chrome
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name. CWE-20
 Improper Input Validation 
CVE-2017-5089 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257155 8.8 HIGH
Network
google
redhat
chrome
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds… CWE-125
Out-of-bounds Read
CVE-2017-5088 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257156 8.8 HIGH
Network
google
redhat
chrome
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a c… CWE-416
 Use After Free
CVE-2017-5087 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257157 6.5 MEDIUM
Network
google
redhat
chrome
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. CWE-20
 Improper Input Validation 
CVE-2017-5086 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257158 6.1 MEDIUM
Network
google chrome Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain operations to run JavaScript on chrome:// pages via … CWE-79
Cross-site Scripting
CVE-2017-5085 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257159 3.3 LOW
Local
google chrome_os Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint. CWE-269
 Improper Privilege Management
CVE-2017-5084 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm
257160 4.3 MEDIUM
Network
google
redhat
chrome
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker contr… CWE-20
 Improper Input Validation 
CVE-2017-5083 2024-11-21 12:27 2017-10-27 Show GitHub Exploit DB Packet Storm