Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
6241 9.8 緊急
Network
Kestra Kestra KestraにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-38428 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
6242 7.2 重要
Network
Gotenberg, Inc. Gotenberg TheCodingMachineのGotenbergにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-39383 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
6243 8.8 重要
Network
Apache Software Foundation Apache NiFi Apache Software FoundationのApache NiFiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-39816 2026-05-11 11:10 2026-05-8 Show GitHub Exploit DB Packet Storm
6244 8.2 重要
Network
Quarkus Quarkus Quarkusにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-39852 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
6245 4.8 警告
Network
Linux Containers Incus Linux ContainersのIncusにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-40243 2026-05-11 11:10 2026-05-6 Show GitHub Exploit DB Packet Storm
6246 7.5 重要
Network
Gotenberg, Inc. Gotenberg TheCodingMachineのGotenbergにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-40280 2026-05-11 11:10 2026-05-5 Show GitHub Exploit DB Packet Storm
6247 8.8 重要
Network
Math.js Math.js Math.jsにおける動的に決定されたオブジェクト属性の不適切に制御された変更に関する脆弱性 CWE-915
動的に決定されたオブジェクト属性の不適切に制御された変更
CVE-2026-41139 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
6248 8.8 重要
Network
OpenEXR OpenEXR OpenEXRにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-41142 2026-05-11 11:10 2026-05-7 Show GitHub Exploit DB Packet Storm
6249 7.7 重要
Network
Istio Istio Istioにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41413 2026-05-11 11:09 2026-05-7 Show GitHub Exploit DB Packet Storm
6250 8.1 重要
Network
Mervin Praison (MervinPraison) PraisonAI Mervin Praison (MervinPraison)のPraisonAI等の複数製品におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-41496 2026-05-11 11:09 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2211 7.8 HIGH
Local
- - Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local att… CWE-428
 Unquoted Search Path or Element
CVE-2016-20090 2026-06-23 06:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2212 8.8 HIGH
Network
- - PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_… CWE-863
 Incorrect Authorization
CVE-2026-56075 2026-06-23 06:15 2026-06-19 Show GitHub Exploit DB Packet Storm
2213 8.1 HIGH
Network
- - PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks au… CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-56076 2026-06-23 06:15 2026-06-19 Show GitHub Exploit DB Packet Storm
2214 7.8 HIGH
Local
- - Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service pat… CWE-428
 Unquoted Search Path or Element
CVE-2016-20085 2026-06-23 06:14 2026-06-20 Show GitHub Exploit DB Packet Storm
2215 7.8 HIGH
Local
- - TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can p… CWE-428
 Unquoted Search Path or Element
CVE-2020-37250 2026-06-23 06:14 2026-06-20 Show GitHub Exploit DB Packet Storm
2216 7.8 HIGH
Local
- - Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers c… CWE-428
 Unquoted Search Path or Element
CVE-2016-20091 2026-06-23 06:14 2026-06-20 Show GitHub Exploit DB Packet Storm
2217 4.8 MEDIUM
Physics
- - capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook t… CWE-287
Improper Authentication
CVE-2026-56294 2026-06-23 06:14 2026-06-21 Show GitHub Exploit DB Packet Storm
2218 - - - In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts. CWE-79
Cross-site Scripting
CVE-2026-8296 2026-06-23 05:44 2026-06-19 Show GitHub Exploit DB Packet Storm
2219 - - - Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in th… CWE-285
Improper Authorization
CVE-2026-12673 2026-06-23 05:44 2026-06-20 Show GitHub Exploit DB Packet Storm
2220 9.1 CRITICAL
Network
- - Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a … CWE-125
Out-of-bounds Read
CVE-2025-62821 2026-06-23 05:44 2026-06-19 Show GitHub Exploit DB Packet Storm