|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 17, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 5611 | 9.3 |
緊急
Network |
GeoVision | GV-IP Device Utility | GeoVisionのGV-IP Device Utilityにおける隠蔽によるセキュリティへの依存に関する脆弱性 |
CWE-656
隠蔽によるセキュリティへの依存 |
CVE-2026-7161 | 2026-05-7 11:31 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
| 5612 | 6.1 |
警告
Network |
GeoVision |
GV-LPC2211 Firmware GV-LPC2011 Firmware |
GeoVisionのGV-LPC2011 Firmware等の複数製品におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2026-7371 | 2026-05-7 11:31 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
| 5613 | 9 |
緊急
Network |
GeoVision | GV-VMS Firmware | GeoVisionのGV-VMS Firmwareにおける境界外書き込みに関する脆弱性 |
CWE-787
境界外書き込み |
CVE-2026-7372 | 2026-05-7 11:31 | 2026-05-4 | Show | GitHub Exploit DB Packet Storm |
| 5614 | 7.8 |
重要
Local |
Zurich Instruments | LabOne Q | Zurich InstrumentsのLabOne Qにおける信頼できないデータのデシリアライゼーションに関する脆弱性 |
CWE-502
信頼性のないデータのデシリアライゼーション |
CVE-2026-7584 | 2026-05-7 11:31 | 2026-05-1 | Show | GitHub Exploit DB Packet Storm |
| 5615 | 9.8 |
緊急
Network |
Shenzhen Tenda Technology Co.,Ltd. | W308R Firmware | Shenzhen Tenda Technology Co.,Ltd.のW308R Firmwareにおけるスプーフィングによる認証回避に関する脆弱性 |
CWE-290
スプーフィングによる認証回避 |
CVE-2018-25316 | 2026-05-7 11:31 | 2026-04-29 | Show | GitHub Exploit DB Packet Storm |
| 5616 | 9.8 |
緊急
Network |
Shenzhen Tenda Technology Co.,Ltd. |
W3002R Firmware A302 Firmware W309R Firmware |
Shenzhen Tenda Technology Co.,Ltd.のA302 Firmware等の複数製品におけるスプーフィングによる認証回避に関する脆弱性 |
CWE-290
スプーフィングによる認証回避 |
CVE-2018-25317 | 2026-05-7 11:31 | 2026-04-29 | Show | GitHub Exploit DB Packet Storm |
| 5617 | 9.8 |
緊急
Network |
Shenzhen Tenda Technology Co.,Ltd. |
FH303 Firmware A300 Firmware |
Shenzhen Tenda Technology Co.,Ltd.のA300 Firmware等の複数製品におけるスプーフィングによる認証回避に関する脆弱性 |
CWE-290
スプーフィングによる認証回避 |
CVE-2018-25318 | 2026-05-7 11:31 | 2026-04-29 | Show | GitHub Exploit DB Packet Storm |
| 5618 | 9.8 |
緊急
Network |
DeanWu (pylixm) | Django-mdeditor | DeanWu (pylixm)のDjango-mdeditorにおける重要な機能に対する認証の欠如に関する脆弱性 |
CWE-306
重要な機能に対する認証の欠如 解説 |
CVE-2025-13030 | 2026-05-7 11:31 | 2026-04-30 | Show | GitHub Exploit DB Packet Storm |
| 5619 | 7.8 |
重要
Local |
The Qt Company | qtdeclarative | The Qt Companyのqtdeclarativeにおける複数の脆弱性 |
CWE-20 CWE-94 CWE-94 |
CVE-2025-14576 | 2026-05-7 11:30 | 2026-04-30 | Show | GitHub Exploit DB Packet Storm |
| 5620 | 6.4 |
警告
Local |
レッドハット | OpenShift Update Service (OSUS) | レッドハットのOpenShift Update Service (OSUS)における不適切なデフォルトパーミッションに関する脆弱性 |
CWE-276
不適切なデフォルトパーミッション |
CVE-2025-57854 | 2026-05-7 11:30 | 2026-04-8 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 17, 2026, 4:19 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1541 | 9.8 |
CRITICAL
Network |
buffalo | open_xdmod | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web s… |
CWE-78
OS Command |
CVE-2026-45777 | 2026-06-11 06:06 | 2026-06-6 | Show | GitHub Exploit DB Packet Storm |
| 1542 | 5.4 |
MEDIUM
Network |
buffalo | open_xdmod | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abus… |
CWE-79
Cross-site Scripting |
CVE-2026-45778 | 2026-06-11 06:05 | 2026-06-6 | Show | GitHub Exploit DB Packet Storm |
| 1543 | 9.8 |
CRITICAL
Network |
buffalo | open_xdmod | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to… |
CWE-89
SQL Injection |
CVE-2026-45779 | 2026-06-11 06:04 | 2026-06-6 | Show | GitHub Exploit DB Packet Storm |
| 1544 | 6.8 |
MEDIUM
Physics |
microsoft |
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w… |
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
CWE-284 NVD-CWE-noinfo Improper Access Control |
CVE-2026-45658 | 2026-06-11 05:59 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 1545 | - | - | - | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
CWE-502
Deserialization of Untrusted Data |
CVE-2026-44963 | 2026-06-11 05:58 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm | |
| 1546 | 7.1 |
HIGH
Adjacent |
microsoft |
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2025 |
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. |
CWE-190
Integer Overflow or Wraparound |
CVE-2026-47288 | 2026-06-11 05:57 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 1547 | 9.8 |
CRITICAL
Network |
microsoft |
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w… |
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
CWE-122 CWE-190 Heap-based Buffer Overflow Integer Overflow or Wraparound |
CVE-2026-47291 | 2026-06-11 05:54 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 1548 | 5.4 |
MEDIUM
Network |
microsoft | sharepoint_server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
CWE-74 CWE-79 Injection Cross-site Scripting |
CVE-2026-47634 | 2026-06-11 05:49 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 1549 | 5.4 |
MEDIUM
Network |
microsoft | sharepoint_server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
CWE-79
Cross-site Scripting |
CVE-2026-47636 | 2026-06-11 05:47 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 1550 | 9.8 |
CRITICAL
Network |
microsoft |
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025 |
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
CWE-122 CWE-416 Heap-based Buffer Overflow Use After Free |
CVE-2026-45657 | 2026-06-11 05:44 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |