Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 12:20 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5641 9.1 緊急
Network
HCL Technologies Limited DFX Analytics HCL Technologies LimitedのDFX Analyticsにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-59852 2026-05-11 11:03 2026-05-6 Show GitHub Exploit DB Packet Storm
5642 5.3 警告
Network
HCL Technologies Limited DFX Analytics HCL Technologies LimitedのDFX Analyticsにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-59853 2026-05-11 11:03 2026-05-6 Show GitHub Exploit DB Packet Storm
5643 6.1 警告
Network
HCL Technologies Limited DFX Analytics HCL Technologies LimitedのDFX Analyticsにおける複数の脆弱性 CWE-79
CWE-80
CVE-2025-59854 2026-05-11 11:03 2026-05-6 Show GitHub Exploit DB Packet Storm
5644 9.4 緊急
Network
Deutsche Telekom AG Telekom Account Management Portal Deutsche Telekom AGのTelekom Account Management Portalにおけるパスワード管理機能に関する脆弱性 CWE-640
パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み
CVE-2025-69614 2026-05-11 11:03 2026-03-10 Show GitHub Exploit DB Packet Storm
5645 9.1 緊急
Network
Deutsche Telekom AG Telekom Account Management Portal Deutsche Telekom AGのTelekom Account Management Portalにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2025-69615 2026-05-11 11:03 2026-03-10 Show GitHub Exploit DB Packet Storm
5646 6.1 警告
Network
generatedata generatedata generatedataにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-70025 2026-05-11 11:02 2026-03-10 Show GitHub Exploit DB Packet Storm
5647 7.5 重要
Network
pdfmake project pdfmake pdfmakeにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-26801 2026-05-11 11:02 2026-03-10 Show GitHub Exploit DB Packet Storm
5648 7.8 重要
Local
Luis Novo (lfnovo) Open Notebook Luis Novo (lfnovo)のOpen Notebookにおける複数の脆弱性 CWE-20
CWE-352
CWE-917
CWE-noinfo
CVE-2026-28201 2026-05-11 11:02 2026-05-7 Show GitHub Exploit DB Packet Storm
5649 9.8 緊急
Network
Xiaomi MIUI File Explorer XiaomiのMIUI File Explorerにおける複数の脆弱性 CWE-303
CWE-862
CVE-2026-29515 2026-05-11 11:02 2026-03-11 Show GitHub Exploit DB Packet Storm
5650 6.1 警告
Network
WorkflowFirst Software LLC Staff.Wiki WorkflowFirst Software LLCのStaff.Wikiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-29969 2026-05-11 11:02 2026-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2411 9.8 CRITICAL
Network
mbs-solutions universal_gateway_firmware An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. CWE-1393
 Use of Default Password
CVE-2026-35075 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2412 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73
 External Control of File Name or Path
CVE-2026-35076 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2413 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73
 External Control of File Name or Path
CVE-2026-35077 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2414 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73
 External Control of File Name or Path
CVE-2026-35078 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2415 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73
 External Control of File Name or Path
CVE-2026-35079 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2416 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73
 External Control of File Name or Path
CVE-2026-35080 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2417 8.1 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. CWE-20
 Improper Input Validation 
CVE-2026-35081 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2418 8.8 HIGH
Network
mbs-solutions universal_gateway_firmware The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. CWE-22
Path Traversal
CVE-2026-35082 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2419 8.8 HIGH
Network
mbs-solutions universal_gateway_firmware A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. CWE-121
Stack-based Buffer Overflow
CVE-2026-35083 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm
2420 8.8 HIGH
Network
mbs-solutions universal_gateway_firmware A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. CWE-121
Stack-based Buffer Overflow
CVE-2026-35084 2026-06-9 02:17 2026-06-3 Show GitHub Exploit DB Packet Storm