Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5381 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC9 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のAC9 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6015 2026-05-1 10:42 2026-04-10 Show GitHub Exploit DB Packet Storm
5382 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC9 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のAC9 ファームウェアにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6016 2026-05-1 10:42 2026-04-10 Show GitHub Exploit DB Packet Storm
5383 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. i6 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のi6 ファームウェアにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-6024 2026-05-1 10:42 2026-04-10 Show GitHub Exploit DB Packet Storm
5384 8.8 重要
Network
MetaGPT MetaGPT MetaGPTにおける複数の脆弱性 CWE-352
CWE-862
CVE-2026-6109 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5385 9.8 緊急
Network
MetaGPT MetaGPT MetaGPTにおける複数の脆弱性 CWE-74
CWE-94
CVE-2026-6110 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5386 6.5 警告
Network
MetaGPT MetaGPT MetaGPTにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-6111 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5387 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F451 Firmware Shenzhen Tenda Technology Co.,Ltd.のF451 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6120 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5388 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F451 Firmware Shenzhen Tenda Technology Co.,Ltd.のF451 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6121 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5389 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F451 Firmware Shenzhen Tenda Technology Co.,Ltd.のF451 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6122 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
5390 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. F451 Firmware Shenzhen Tenda Technology Co.,Ltd.のF451 Firmwareにおける複数の脆弱性 CWE-119
CWE-121
CVE-2026-6123 2026-05-1 10:42 2026-04-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1191 7.5 HIGH
Network
- - Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() functio… CWE-78
OS Command 
CVE-2026-40519 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1192 7.1 HIGH
Network
- - WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by su… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-49141 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1193 3.5 LOW
Network
- - The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrato… CWE-79
Cross-site Scripting
CVE-2026-8981 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1194 - - - SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be a… CWE-89
SQL Injection
CVE-2026-10731 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1195 8.2 HIGH
Network
- - Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST pa… CWE-89
SQL Injection
CVE-2016-20062 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1196 7.1 HIGH
Network
- - Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attac… CWE-89
SQL Injection
CVE-2016-20063 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1197 6.2 MEDIUM
Local
- - WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attacke… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2016-20064 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1198 8.2 HIGH
Network
- - Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selec… CWE-89
SQL Injection
CVE-2016-20065 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1199 8.2 HIGH
Network
- - WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… CWE-89
SQL Injection
CVE-2017-20243 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
1200 8.2 HIGH
Network
- - Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. … CWE-89
SQL Injection
CVE-2017-20244 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm