Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
6741 7.8 重要
Local
The Qt Company qtdeclarative The Qt Companyのqtdeclarativeにおける複数の脆弱性 CWE-20
CWE-94
CWE-94
CVE-2025-14576 2026-05-7 11:30 2026-04-30 Show GitHub Exploit DB Packet Storm
6742 6.4 警告
Local
レッドハット OpenShift Update Service (OSUS) レッドハットのOpenShift Update Service (OSUS)における不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57854 2026-05-7 11:30 2026-04-8 Show GitHub Exploit DB Packet Storm
6743 5.4 警告
Network
Wolters Kluwer Financial Services, Inc. LEX Baza Dokumentow Wolters Kluwer Financial Services, Inc.のLEX Baza Dokumentowにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-1493 2026-05-7 11:30 2026-04-30 Show GitHub Exploit DB Packet Storm
6744 5.7 警告
Adjacent
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-20020 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
6745 6.1 警告
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-80
クロスサイトスクリプティング (Basic XSS)
CVE-2026-20070 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
6746 5.8 警告
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品におけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-20073 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
6747 7.7 重要
Network
シスコシステムズ Firepower Threat Defense (FTD)
Adaptive Security Appliance (ASA) Software
シスコシステムズのAdaptive Security Appliance (ASA) Software等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2026-20100 2026-05-7 11:30 2026-03-4 Show GitHub Exploit DB Packet Storm
6748 8.6 重要
Network
NVIDIA NemoClaw NVIDIAのNemoClawにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-24222 2026-05-7 11:30 2026-04-28 Show GitHub Exploit DB Packet Storm
6749 6.3 警告
Local
NVIDIA NemoClaw NVIDIAのNemoClawにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-24231 2026-05-7 11:30 2026-04-28 Show GitHub Exploit DB Packet Storm
6750 6.5 警告
Network
SAP Manage Reference Structures SAPのManage Reference Structuresにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-27679 2026-05-7 11:30 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
541 - - - Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the requi… New CWE-863
 Incorrect Authorization
CVE-2026-54573 2026-06-26 05:21 2026-06-26 Show GitHub Exploit DB Packet Storm
542 3.5 LOW
Network
- - HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario. New CWE-284
CWE-319
Improper Access Control
Cleartext Transmission of Sensitive Information
CVE-2025-15619 2026-06-26 05:20 2026-06-24 Show GitHub Exploit DB Packet Storm
543 9.8 CRITICAL
Network
- - Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requ… New CWE-306
Missing Authentication for Critical Function
CVE-2026-49980 2026-06-26 05:20 2026-06-25 Show GitHub Exploit DB Packet Storm
544 7.6 HIGH
Network
- - A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's b… New CWE-791
 Incomplete Filtering of Special Elements
CVE-2026-11998 2026-06-26 05:20 2026-06-25 Show GitHub Exploit DB Packet Storm
545 - - - Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a… New CWE-770
CWE-789
 Allocation of Resources Without Limits or Throttling
 Memory Allocation with Excessive Size Value
CVE-2026-54448 2026-06-26 05:20 2026-06-26 Show GitHub Exploit DB Packet Storm
546 2.5 LOW
Local
cacti cacti Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric value… New CWE-474
 Use of Function with Inconsistent Implementations
CVE-2026-39894 2026-06-26 05:19 2026-06-25 Show GitHub Exploit DB Packet Storm
547 7.6 HIGH
Network
- - Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's … New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-55583 2026-06-26 05:18 2026-06-25 Show GitHub Exploit DB Packet Storm
548 9.0 CRITICAL
Network
- - LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-54157 2026-06-26 05:18 2026-06-24 Show GitHub Exploit DB Packet Storm
549 9.6 CRITICAL
Network
- - immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows a… New CWE-79
CWE-601
Cross-site Scripting
Open Redirect
CVE-2026-53662 2026-06-26 05:18 2026-06-24 Show GitHub Exploit DB Packet Storm
550 - - - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap … New CWE-120
Classic Buffer Overflow
CVE-2026-54257 2026-06-26 05:18 2026-06-24 Show GitHub Exploit DB Packet Storm