|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 26, 2026, 10:01 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 731 | 4.9 |
警告
Network |
Apache Software Foundation | Apache DolphinScheduler | Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 |
CWE-863
不正な認証 |
CVE-2026-41280 | 2026-06-22 11:38 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 732 | 6.1 |
警告
Network |
VMware | Spring Security | VMwareのSpring Securityにおけるオープンリダイレクトの脆弱性 |
CWE-601
オープンリダイレクト |
CVE-2026-41706 | 2026-06-22 11:37 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 733 | 6.5 |
警告
Network |
Apache Software Foundation | Apache DolphinScheduler | Apache Software FoundationのApache DolphinSchedulerにおける不正な認証に関する脆弱性 |
CWE-863
不正な認証 |
CVE-2026-42357 | 2026-06-22 11:37 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 734 | 7.2 |
重要
Network |
OpenStack | OpenStack Ironic | OpenStackのOpenStack Ironicにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 |
CWE-829
信頼性のない制御領域からの機能の組み込み |
CVE-2026-42510 | 2026-06-22 11:37 | 2026-04-28 | Show | GitHub Exploit DB Packet Storm |
| 735 | 7.5 |
重要
Network |
マイクロソフト |
Microsoft Windows 11 26h1 Microsoft Windows Server 2022 Microsoft Windows 10 22h2 Microsoft Windows 10 1607 Microsoft Wind… |
Windows リモート デスクトップ プロトコル (RDP) の情報漏えいの脆弱性 |
CWE-125
境界外読み取り |
CVE-2026-42908 | 2026-06-22 11:37 | 2026-06-9 | Show | GitHub Exploit DB Packet Storm |
| 736 | 7.5 |
重要
Network |
マイクロソフト |
Microsoft Windows 11 26h1 Microsoft Windows Server 2022 Microsoft Windows Server 2025 Microsoft Windows 11 25h2 Microsoft … |
リモート デスクトップ クライアントのリモートでコードが実行される脆弱性 |
CWE-362 CWE-362 CWE-416 CWE-787 |
CVE-2026-42913 | 2026-06-22 11:37 | 2026-06-9 | Show | GitHub Exploit DB Packet Storm |
| 737 | 6.7 |
警告
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 |
CWE-121
スタックオーバーフロー |
CVE-2026-42919 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 738 | 7.5 |
重要
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品における無限ループに関する脆弱性 |
CWE-835
無限ループ |
CVE-2026-42920 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 739 | 8.7 |
重要
Network |
F5 Networks |
BIG-IP WebSafe big-ip container ingress services BIG-IP Application Security Manager (ASM) BIG-IP Advanced Web Application Firewal… |
F5 NetworksのBIG-IP Access Policy Manager (APM)等の複数製品におけるOS コマンドインジェクションの脆弱性 |
CWE-78
OSコマンド・インジェクション |
CVE-2026-42924 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
| 740 | 5.8 |
警告
Network |
F5 Networks |
nginx open source NGINX Gateway Fabric NGINX Ingress Controller NGINX Instance Manager |
F5 NetworksのNGINX Gateway Fabric等の複数製品におけるエンコーディングエラーに関する脆弱性 |
CWE-172
エンコーディングエラー |
CVE-2026-42926 | 2026-06-22 11:37 | 2026-05-13 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 26, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 257011 | 7.5 |
HIGH
Network |
redhat mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox firefox_esr thun… |
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This all… |
CWE-200
Information Exposure |
CVE-2017-5454 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257012 | 4.3 |
MEDIUM
Network |
redhat mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox firefox_esr thun… |
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to b… |
CWE-20
Improper Input Validation |
CVE-2017-5451 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257013 | 7.5 |
HIGH
Network |
redhat mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox_esr thunderbird … |
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, … |
CWE-20
Improper Input Validation |
CVE-2017-5449 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257014 | 8.6 |
HIGH
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox_esr | An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechan… |
CWE-787
Out-of-bounds Write |
CVE-2017-5448 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257015 | 9.1 |
CRITICAL
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This… |
CWE-416
Use After Free |
CVE-2017-5447 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257016 | 9.8 |
CRITICAL
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 5… |
CWE-125
Out-of-bounds Read |
CVE-2017-5446 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257017 | 9.8 |
CRITICAL
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. |
CWE-787
Out-of-bounds Write |
CVE-2017-5443 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257018 | 9.8 |
CRITICAL
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45… |
CWE-416
Use After Free |
CVE-2017-5442 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257019 | 9.8 |
CRITICAL
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firef… |
CWE-416
Use After Free |
CVE-2017-5441 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |
| 257020 | 7.5 |
HIGH
Network |
debian redhat mozilla |
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird | A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arra… |
CWE-129
Improper Validation of Array Index |
CVE-2017-5445 | 2024-11-21 12:27 | 2018-06-12 | Show | GitHub Exploit DB Packet Storm |