Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5471 6.1 警告
Network
WSO2 WSO2 API Manager WSO2のWSO2 API Managerにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-10242 2026-04-24 11:35 2026-04-16 Show GitHub Exploit DB Packet Storm
5472 9.1 緊急
Network
WSO2 Identity Server as Key Manager
WSO2 API Manager
WSO2 Identity Server
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2のWSO2 API Manager等の複数製品におけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2024-2374 2026-04-24 11:35 2026-04-16 Show GitHub Exploit DB Packet Storm
5473 5.4 警告
Network
WSO2 WSO2 API Manager WSO2のWSO2 API Managerにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4867 2026-04-24 11:34 2026-04-16 Show GitHub Exploit DB Packet Storm
5474 7.5 重要
Network
WSO2 WSO2 API Manager WSO2のWSO2 API ManagerにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2024-8010 2026-04-24 11:34 2026-04-16 Show GitHub Exploit DB Packet Storm
5475 5.4 警告
Network
WSO2 WSO2 Identity Server WSO2のWSO2 Identity Serverにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2025-12624 2026-04-24 11:34 2026-04-16 Show GitHub Exploit DB Packet Storm
5476 8.2 重要
Network
HCL Technologies Limited HCL BigFix Service Management (SM) HCL Technologies LimitedのHCL BigFix Service Management (SM)におけるHTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2025-31958 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5477 5.3 警告
Network
HCL Technologies Limited HCL BigFix Service Management (SM) HCL Technologies LimitedのHCL BigFix Service Management (SM)における重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-31981 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5478 6.1 警告
Network
WSO2 WSO2 API Manager
WSO2 Identity Server
WSO2のWSO2 API Manager等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-6024 2026-04-24 11:34 2026-04-16 Show GitHub Exploit DB Packet Storm
5479 6.5 警告
Network
フォーティネット FortiOS
FortiPAM
FortiProxy
FortiSwitch Manager
フォーティネットのFortiOS等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-61624 2026-04-24 11:34 2026-04-14 Show GitHub Exploit DB Packet Storm
5480 5.4 警告
Network
フォーティネット FortiSandbox
FortiSandbox Cloud
フォーティネットのFortiSandbox等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-61886 2026-04-24 11:34 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 6.5 MEDIUM
Network
- - Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security… New CWE-457
 Use of Uninitialized Variable
CVE-2026-11067 2026-06-6 03:16 2026-06-5 Show GitHub Exploit DB Packet Storm
72 8.8 HIGH
Network
- - Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sand… New CWE-20
 Improper Input Validation 
CVE-2026-11041 2026-06-6 03:16 2026-06-5 Show GitHub Exploit DB Packet Storm
73 6.5 MEDIUM
Network
- - Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) New CWE-125
Out-of-bounds Read
CVE-2026-10985 2026-06-6 03:16 2026-06-5 Show GitHub Exploit DB Packet Storm
74 5.4 MEDIUM
Network
- - Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity:… New CWE-451
 User Interface (UI) Misrepresentation of Critical Information
CVE-2026-10984 2026-06-6 03:16 2026-06-5 Show GitHub Exploit DB Packet Storm
75 9.6 CRITICAL
Network
- - Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit… New CWE-20
 Improper Input Validation 
CVE-2026-10983 2026-06-6 03:16 2026-06-5 Show GitHub Exploit DB Packet Storm
76 9.8 CRITICAL
Network
- - NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html… New CWE-306
Missing Authentication for Critical Function
CVE-2025-71318 2026-06-6 03:16 2026-06-6 Show GitHub Exploit DB Packet Storm
77 9.8 CRITICAL
Network
- - NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/log… New CWE-798
 Use of Hard-coded Credentials
CVE-2025-71317 2026-06-6 03:16 2026-06-6 Show GitHub Exploit DB Packet Storm
78 8.8 HIGH
Network
amazon kiro_ide Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions… Update CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-10591 2026-06-6 02:45 2026-06-3 Show GitHub Exploit DB Packet Storm
79 9.6 CRITICAL
Network
google chrome Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) New CWE-416
 Use After Free
CVE-2026-10886 2026-06-6 02:42 2026-06-5 Show GitHub Exploit DB Packet Storm
80 8.8 HIGH
Network
google chrome Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) New CWE-416
 Use After Free
CVE-2026-10885 2026-06-6 02:42 2026-06-5 Show GitHub Exploit DB Packet Storm