Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4971 6.5 警告
Network
jellyfin jellyfin jellyfinにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-35034 2026-04-27 11:22 2026-04-14 Show GitHub Exploit DB Packet Storm
4972 8.8 重要
Network
Glances project Glances Nicolas Hennion (nicolargo)のGlancesにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35587 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
4973 9.3 緊急
Network
nanobot nanobot nanobotにおける WebSocket でのオリジン検証の欠如に関する脆弱性 CWE-1385
WebSocket でのオリジン検証の欠如
CVE-2026-35589 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
4974 8.8 重要
Network
webkul krayin crm webkulのkrayin crmにおける複数の脆弱性 CWE-269
CWE-639
CVE-2026-38529 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
4975 8.1 重要
Network
webkul krayin crm webkulのkrayin crmにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-38530 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
4976 8.1 重要
Network
webkul krayin crm webkulのkrayin crmにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-38532 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
4977 5.4 警告
Network
Istio Istio Istioにおける複数の脆弱性 CWE-185
CWE-863
CVE-2026-39350 2026-04-27 11:21 2026-04-15 Show GitHub Exploit DB Packet Storm
4978 6.5 警告
Network
Project Jupyter nbconvert Project Jupyterのnbconvertにおける複数の脆弱性 CWE-22
CWE-73
CVE-2026-39377 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
4979 6.5 警告
Network
Project Jupyter nbconvert Project Jupyterのnbconvertにおける複数の脆弱性 CWE-22
CWE-73
CVE-2026-39378 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
4980 7.2 重要
Network
boidcms boidcms boidcmsにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2026-39387 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1111 7.8 HIGH
Local
google android In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional e… Update CWE-20
 Improper Input Validation 
CVE-2026-0078 2026-06-4 01:57 2026-06-2 Show GitHub Exploit DB Packet Storm
1112 9.8 CRITICAL
Network
gitlawb openclaude OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashToo… Update CWE-284
CWE-306
Improper Access Control
Missing Authentication for Critical Function
CVE-2026-42074 2026-06-4 01:54 2026-06-3 Show GitHub Exploit DB Packet Storm
1113 6.5 MEDIUM
Network
gitlawb openclaude OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv… Update CWE-352
CWE-400
 Origin Validation Error
 Uncontrolled Resource Consumption
CVE-2026-42073 2026-06-4 01:54 2026-06-3 Show GitHub Exploit DB Packet Storm
1114 5.4 MEDIUM
Network
shopify react-router React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cros… Update CWE-79
Cross-site Scripting
CVE-2026-33244 2026-06-4 01:54 2026-06-3 Show GitHub Exploit DB Packet Storm
1115 5.3 MEDIUM
Network
oracle rest_data_services Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac… Update CWE-284
Improper Access Control
CVE-2026-46842 2026-06-4 01:53 2026-05-29 Show GitHub Exploit DB Packet Storm
1116 7.5 HIGH
Network
opentelemetry ebpf_instrumentation OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcac… Update CWE-190
 Integer Overflow or Wraparound
CVE-2026-45686 2026-06-4 01:52 2026-06-3 Show GitHub Exploit DB Packet Storm
1117 7.5 HIGH
Network
opentelemetry ebpf_instrumentation OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught … Update CWE-20
CWE-248
CWE-704
 Improper Input Validation 
 Uncaught Exception
 Incorrect Type Conversion or Cast
CVE-2026-45685 2026-06-4 01:52 2026-06-3 Show GitHub Exploit DB Packet Storm
1118 5.3 MEDIUM
Network
oracle rest_data_services Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-46843 2026-06-4 01:52 2026-05-29 Show GitHub Exploit DB Packet Storm
1119 5.3 MEDIUM
Local
opentelemetry ebpf_instrumentation OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by readi… Update CWE-126
CWE-787
 Buffer Over-read
 Out-of-bounds Write
CVE-2026-45684 2026-06-4 01:52 2026-06-3 Show GitHub Exploit DB Packet Storm
1120 3.8 LOW
Local
opentelemetry ebpf_instrumentation OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_pr… Update CWE-127
CWE-200
 Buffer Under-read
Information Exposure
CVE-2026-45683 2026-06-4 01:52 2026-06-3 Show GitHub Exploit DB Packet Storm