Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
801 7.8 重要
Local
opentelemetry OpenTelemetry.Exporter.OpenTelemetryProtocol opentelemetryのOpenTelemetry.Exporter.OpenTelemetryProtocolにおけるアクセスパーミションのディレクトリの一時ファイル作成に関する脆弱性 CWE-379
不適切なアクセスパーミションのディレクトリに一時ファイル作成
CVE-2026-42191 2026-05-28 14:33 2026-05-12 Show GitHub Exploit DB Packet Storm
802 7.5 重要
Network
Absinthe-graphql Absinthe Absinthe-graphqlのAbsintheにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42793 2026-05-28 14:32 2026-05-8 Show GitHub Exploit DB Packet Storm
803 7.5 重要
Network
Absinthe-graphql Absinthe Absinthe-graphqlのAbsintheにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-43967 2026-05-28 14:32 2026-05-8 Show GitHub Exploit DB Packet Storm
804 6.1 警告
Network
The Kyverno Authors Policy-reporter-ui The Kyverno AuthorsのPolicy-reporter-uiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44245 2026-05-28 14:32 2026-05-12 Show GitHub Exploit DB Packet Storm
805 8.6 重要
Network
Marginal v1-core Marginalのv1-coreにおける数値型間の変換の誤りに関する脆弱性 CWE-681
数値型間の変換の誤り
CVE-2026-4931 2026-05-28 14:32 2026-04-7 Show GitHub Exploit DB Packet Storm
806 7.4 重要
Network
Project Jupyter Jupyter Server Jupyter Serverにおけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2025-61669 2026-05-28 12:05 2026-05-28 Show GitHub Exploit DB Packet Storm
807 - - 日立 Hitachi Application Server
uCosminexus Application Runtime with Java for Apache Tomcat
uCosminexus Application Runtime with Java…
Cosminexusにおける複数の脆弱性 - CVE-2026-22007
CVE-2026-22013
CVE-2026-22016
CVE-2026-22018
CVE-2026-22021
CVE-2026-23865
CVE-2026-34268
CVE-2026-34282
2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
808 - - 日立 Hitachi Automation Director
Hitachi Replication Manager
Hitachi Configuration Manager
Hitachi Ops Center API Configuration Manager
H…
Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品における複数の脆弱性 - CVE-2026-22007
CVE-2026-22013
CVE-2026-22016
CVE-2026-22018
CVE-2026-22021
CVE-2026-23865
CVE-2026-34268
CVE-2026-34282
2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
809 - - 日立 Hitachi Infrastructure Analytics Advisor
Hitachi Ops Center Analyzer
Hitachi Ops Center Analyzer viewpoint
Hitachi Infrastructure Analytics Advisor,Hitachi Ops Center AnalyzerおよびHitachi Ops Center Analyzer viewpointにおける脆弱性 - CVE-2026-3314 2026-05-27 13:53 2026-05-26 Show GitHub Exploit DB Packet Storm
810 - - LMSYS Org SGLang SGLangにおける複数の脆弱性 - CVE-2026-5760
CVE-2026-7301
CVE-2026-7302
CVE-2026-7304
2026-05-27 12:17 2026-05-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2501 8.3 HIGH
Network
- - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (… CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-9998 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm
2502 8.3 HIGH
Network
- - Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-9988 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm
2503 8.3 HIGH
Network
- - Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT… CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-9966 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm
2504 7.3 HIGH
Network
- - A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. T… CWE-74
CWE-707
Injection
 Improper Enforcement of Message or Data Structure
CVE-2026-9422 2026-05-30 01:16 2026-05-25 Show GitHub Exploit DB Packet Storm
2505 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid… - CVE-2026-9194 2026-05-30 01:16 2026-05-30 Show GitHub Exploit DB Packet Storm
2506 7.3 HIGH
Network
- - IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2026-48961 2026-05-30 01:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2507 7.5 HIGH
Network
- - IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) agains… CWE-407
 Inefficient Algorithmic Complexity
CVE-2026-48959 2026-05-30 01:16 2026-05-27 Show GitHub Exploit DB Packet Storm
2508 9.9 CRITICAL
Network
- - Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Eas… CWE-269
CWE-284
CWE-306
 Improper Privilege Management
Improper Access Control
Missing Authentication for Critical Function
CVE-2026-46824 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm
2509 7.7 HIGH
Network
- - Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily ex… CWE-863
 Incorrect Authorization
CVE-2026-46823 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm
2510 9.9 CRITICAL
Network
- - Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all… CWE-284
Improper Access Control
CVE-2026-46822 2026-05-30 01:16 2026-05-29 Show GitHub Exploit DB Packet Storm