Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189991 6.1 警告
Network
Vanguard - Vanguard Marketplace Digital Products PHP におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-17937 2018-01-25 11:51 2017-12-28 Show GitHub Exploit DB Packet Storm
189992 8.8 重要
Network
Vanguard - Vanguard Marketplace Digital Products PHP におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-17936 2018-01-25 11:51 2017-12-28 Show GitHub Exploit DB Packet Storm
189993 7.5 重要
Network
ivan kartolo - TYPO3 用の Direct Mail エクステンションにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2013-7400 2018-01-25 11:47 2013-09-25 Show GitHub Exploit DB Packet Storm
189994 6.1 警告
Network
Mistune project
Fedora Project
- Mistune におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-16876 2018-01-25 11:25 2017-11-7 Show GitHub Exploit DB Packet Storm
189995 8.1 重要
Network
Embedthis Software, LLC - Embedthis GoAhead における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-17562 2018-01-25 11:11 2017-06-10 Show GitHub Exploit DB Packet Storm
189996 9.6 緊急
Network
Atlassian - Atlassian Bamboo における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-14589 2018-01-25 11:11 2017-12-5 Show GitHub Exploit DB Packet Storm
189997 9.8 緊急
Network
DozerMapper - Dozer における信頼性のないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2014-9515 2018-01-25 10:27 2014-12-5 Show GitHub Exploit DB Packet Storm
189998 7.8 重要
Local
Mozilla Foundation - Mozilla Network Security Services におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-11698 2018-01-25 10:22 2017-08-9 Show GitHub Exploit DB Packet Storm
189999 7.8 重要
Local
Mozilla Foundation - Mozilla Network Security Services におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-11697 2018-01-25 10:22 2017-08-9 Show GitHub Exploit DB Packet Storm
190000 7.8 重要
Local
Mozilla Foundation - Mozilla Network Security Services におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2017-11696 2018-01-25 10:22 2017-08-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2841 9.1 CRITICAL
Network
- - ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an a… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2026-53609 2026-06-16 05:54 2026-06-13 Show GitHub Exploit DB Packet Storm
2842 7.8 HIGH
Local
- - Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via loca… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-53406 2026-06-16 05:52 2026-06-13 Show GitHub Exploit DB Packet Storm
2843 8.1 HIGH
Network
- - Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privi… CWE-939
 Improper Authorization in Handler for Custom URL Scheme
CVE-2026-53407 2026-06-16 05:52 2026-06-13 Show GitHub Exploit DB Packet Storm
2844 6.5 MEDIUM
Network
- - Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authe… CWE-22
Path Traversal
CVE-2026-11442 2026-06-16 05:52 2026-06-13 Show GitHub Exploit DB Packet Storm
2845 4.6 MEDIUM
Network
- - Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User … CWE-79
Cross-site Scripting
CVE-2026-11443 2026-06-16 05:52 2026-06-13 Show GitHub Exploit DB Packet Storm
2846 7.6 HIGH
Network
- - Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email ad… CWE-306
Missing Authentication for Critical Function
CVE-2026-53981 2026-06-16 05:50 2026-06-13 Show GitHub Exploit DB Packet Storm
2847 6.5 MEDIUM
Network
- - Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletio… CWE-645
 Overly Restrictive Account Lockout Mechanism
CVE-2026-53982 2026-06-16 05:50 2026-06-13 Show GitHub Exploit DB Packet Storm
2848 10.0 CRITICAL
Network
- - SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity toke… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-48558 2026-06-16 05:50 2026-06-13 Show GitHub Exploit DB Packet Storm
2849 4.3 MEDIUM
Network
- - Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated… CWE-459
 Incomplete Cleanup
CVE-2026-53867 2026-06-16 05:50 2026-06-13 Show GitHub Exploit DB Packet Storm
2850 7.5 HIGH
Network
- - Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in… CWE-306
Missing Authentication for Critical Function
CVE-2026-53868 2026-06-16 05:50 2026-06-13 Show GitHub Exploit DB Packet Storm