Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
71 5.4 警告
Network
マイクロソフト Microsoft SharePoint Server Microsoft SharePoint Server のなりすましの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45468 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
72 7 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows 11 26h1
Microsoft Windows 11 24h2
Microsoft Wind…
Windows プログラム互換性アシスタント サービスの特権昇格の脆弱性 New CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-45487 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
73 7.5 重要
Network
Espressif Systems ESP-IDF Espressif SystemsのESP-IDFにおけるNULL ポインタデリファレンスに関する脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2026-45541 2026-06-12 14:50 2026-06-10 Show GitHub Exploit DB Packet Storm
74 7.1 重要
Adjacent
Espressif Systems ESP-IDF Espressif SystemsのESP-IDFにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-45542 2026-06-12 14:50 2026-06-10 Show GitHub Exploit DB Packet Storm
75 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows Collaborative Translation Framework (CTFMON) の特権昇格の脆弱性 New CWE-59
リンク解釈の問題
CVE-2026-45586 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
76 7.9 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
セキュア ブートのセキュリティ機能のバイパスの脆弱性 New CWE-693
保護メカニズムの不具合
CVE-2026-45588 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
77 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows インターネット (wininet.dll) の特権昇格の脆弱性 New CWE-190
CWE-416
CVE-2026-45592 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
78 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11 26h1
Microsoft …
Windows SDK の特権の昇格の脆弱性 New CWE-190
CWE-416
CVE-2026-45593 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
79 5.5 警告
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows アプリケーション ID (AppID) の情報漏えいの脆弱性 New CWE-200
情報漏えい
CVE-2026-45594 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
80 5.4 警告
Network
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft&n…
Windows Mark Of The Web セキュリティ機能のバイパスの脆弱性 New CWE-693
保護メカニズムの不具合
CVE-2026-45595 2026-06-12 14:50 2026-06-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
258251 7.8 HIGH
Local
chitora lhaz\+ Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. CWE-426
 Untrusted Search Path
CVE-2017-2248 2024-11-21 12:23 2017-07-17 Show GitHub Exploit DB Packet Storm
258252 7.8 HIGH
Local
chitora lhaz Untrusted search path vulnerability in Self-extracting archive files created by Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. CWE-426
 Untrusted Search Path
CVE-2017-2247 2024-11-21 12:23 2017-07-17 Show GitHub Exploit DB Packet Storm
258253 7.8 HIGH
Local
chitora lhaz Untrusted search path vulnerability in Installer of Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. CWE-426
 Untrusted Search Path
CVE-2017-2246 2024-11-21 12:23 2017-07-17 Show GitHub Exploit DB Packet Storm
258254 6.3 MEDIUM
Network
hammock assetview SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service". CWE-89
SQL Injection
CVE-2017-2241 2024-11-21 12:23 2017-07-17 Show GitHub Exploit DB Packet Storm
258255 6.5 MEDIUM
Network
hammock assetview Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service". CWE-22
Path Traversal
CVE-2017-2240 2024-11-21 12:23 2017-07-17 Show GitHub Exploit DB Packet Storm
258256 5.0 MEDIUM
Network
getshortcodes shortcodes_ultimate Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors. CWE-22
Path Traversal
CVE-2017-2245 2024-11-21 12:23 2017-07-7 Show GitHub Exploit DB Packet Storm
258257 8.8 HIGH
Network
brother mfc-j960dwn_firmware Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. CWE-352
 Origin Validation Error
CVE-2017-2244 2024-11-21 12:23 2017-07-7 Show GitHub Exploit DB Packet Storm
258258 6.1 MEDIUM
Network
dfactory responsive_lightbox Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2017-2243 2024-11-21 12:23 2017-07-7 Show GitHub Exploit DB Packet Storm
258259 5.3 MEDIUM
Local
marp marp Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript. CWE-200
Information Exposure
CVE-2017-2239 2024-11-21 12:23 2017-07-7 Show GitHub Exploit DB Packet Storm
258260 8.8 HIGH
Network
toshiba hem-gw16a_firmware
hem-gw26a_firmware
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier … CWE-352
 Origin Validation Error
CVE-2017-2238 2024-11-21 12:23 2017-07-7 Show GitHub Exploit DB Packet Storm