|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 3, 2026, 6:08 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 4831 | 5.3 |
警告
Network |
WWBN | AVideo | WWBNのAVideoにおける推測可能な CAPTCHA の脆弱性 |
CWE-804
推測可能な CAPTCHA |
CVE-2026-40935 | 2026-04-27 11:20 | 2026-04-21 | Show | GitHub Exploit DB Packet Storm |
| 4832 | 5.3 |
警告
Network |
WWBN | AVideo | WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 |
CWE-918
サーバサイドリクエストフォージェリ |
CVE-2026-41055 | 2026-04-27 11:20 | 2026-04-21 | Show | GitHub Exploit DB Packet Storm |
| 4833 | 8.1 |
重要
Network |
WWBN | AVideo | WWBNのAVideoにおける過度に許容されるクロスドメインホワイトリストに関する脆弱性 |
CWE-942
過度に許容されるクロスドメインホワイトリスト |
CVE-2026-41056 | 2026-04-27 11:20 | 2026-04-21 | Show | GitHub Exploit DB Packet Storm |
| 4834 | 7.5 |
重要
Network |
libexpat project | libexpat | libexpat projectのlibexpatにおけるエントロピー不足に関する脆弱性 |
CWE-331
エントロピー不足 |
CVE-2026-41080 | 2026-04-27 11:20 | 2026-04-16 | Show | GitHub Exploit DB Packet Storm |
| 4835 | 7.5 |
重要
Network |
free5gc |
free5gc pcf |
free5GCのfree5GC等の複数製品におけるリソースの枯渇に関する脆弱性 |
CWE-400
リソースの枯渇 |
CVE-2026-41135 | 2026-04-27 11:20 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 4836 | 5.3 |
警告
Network |
free5gc |
free5gc amf |
free5GCのamf等の複数製品における予期せぬ動作に関する脆弱性 |
CWE-440
予期せぬ動作 |
CVE-2026-41136 | 2026-04-27 11:20 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 4837 | 8.1 |
重要
Network |
GitLab.org | GitLab | GitLab.orgのGitLabにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2026-4922 | 2026-04-27 11:20 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 4838 | 6.1 |
警告
Network |
GitLab.org | GitLab | GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2026-5262 | 2026-04-27 11:20 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 4839 | 4.3 |
警告
Network |
GitLab.org | GitLab | GitLab.orgのGitLabにおける不正な認証に関する脆弱性 |
CWE-863
不正な認証 |
CVE-2026-5377 | 2026-04-27 11:20 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
| 4840 | 8.1 |
重要
Network |
GitLab.org | GitLab | GitLab.orgのGitLabにおけるパスの等価性の不適切な解決に関する脆弱性 |
CWE-41
パスの等価性の不適切な解決 |
CVE-2026-5816 | 2026-04-27 11:19 | 2026-04-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 4, 2026, 4:17 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 411 | 7.5 |
HIGH
Network |
osgeo | mapserver | MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFil… Update |
CWE-129 CWE-476 Improper Validation of Array Index NULL Pointer Dereference |
CVE-2026-45104 | 2026-06-3 03:19 | 2026-05-28 | Show | GitHub Exploit DB Packet Storm |
| 412 | 5.5 |
MEDIUM
Local |
android | In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed… New |
CWE-400
Uncontrolled Resource Consumption |
CVE-2026-0069 | 2026-06-3 03:06 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm | |
| 413 | 6.5 |
MEDIUM
Adjacent |
qualcomm |
fastconnect_7800_firmware qca7005_firmware snapdragon_ar1_gen_1_platform_firmware wcd9380_firmware wcd9385_firmware wsa8830_firmware wsa8832_firmware wsa8835_firmware |
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. New |
CWE-1230
Exposure of Sensitive Information Through Metadata |
CVE-2025-59601 | 2026-06-3 03:00 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm |
| 414 | 7.8 |
HIGH
Local |
qualcomm |
snapdragon_480_5g_mobile_platform_firmware snapdragon_480\+_5g_mobile_platform_firmware snapdragon_6_gen_1_mobile_platform_firmware snapdragon_6_gen_3_mobile_platform_firmware snapdragon_… |
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. New |
CWE-476
NULL Pointer Dereference |
CVE-2025-59604 | 2026-06-3 03:00 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm |
| 415 | 7.8 |
HIGH
Local |
qualcomm |
snapdragon_g1_gen_2_gaming_platform_firmware ar8035_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6800_firmware fas… |
Memory Corruption when processing device identifier strings that exceed the expected maximum length. New |
CWE-787
Out-of-bounds Write |
CVE-2025-59605 | 2026-06-3 03:00 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm |
| 416 | 7.8 |
HIGH
Local |
qualcomm |
cologne_firmware cq7790_firmware cq8725s_firmware cq8750m_firmware fastconnect_6200_firmware wsa8840_firmware wsa8845_firmware wsa8845h_firmware wsa8850_firmware wsa8850w_f… |
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. New |
CWE-476
NULL Pointer Dereference |
CVE-2025-59606 | 2026-06-3 03:00 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm |
| 417 | 5.5 |
MEDIUM
Network |
qualcomm |
5g_fixed_wireless_access_platform_firmware ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6900_firmware sxr2250p_firmware wcd9340_firmware wcd9370_firmwar… |
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. New |
CWE-126
Buffer Over-read |
CVE-2025-59609 | 2026-06-3 03:00 | 2026-06-2 | Show | GitHub Exploit DB Packet Storm |
| 418 | 7.5 |
HIGH
Network |
ultrajson_project | ultrajson | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an excepti… Update |
CWE-401
Missing Release of Memory after Effective Lifetime |
CVE-2026-44660 | 2026-06-3 03:00 | 2026-05-28 | Show | GitHub Exploit DB Packet Storm |
| 419 | 7.8 |
HIGH
Local |
cnighswonger | claude-code-cache-fix | claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directl… Update |
CWE-78 CWE-94 OS Command Code Injection |
CVE-2026-45136 | 2026-06-3 02:57 | 2026-05-28 | Show | GitHub Exploit DB Packet Storm |
| 420 | 7.8 |
HIGH
Local |
- | - | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admi… New |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2026-40619 | 2026-06-3 02:35 | 2026-06-3 | Show | GitHub Exploit DB Packet Storm |