Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1951 5.4 警告
Network
マイクロソフト Microsoft SharePoint Server Microsoft SharePoint Server のなりすましの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45465 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1952 5.4 警告
Network
マイクロソフト Microsoft SharePoint Server Microsoft SharePoint Server のなりすましの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45479 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1953 7.8 重要
Local
マイクロソフト Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Microsoft Windows 11 25h2
Windows カーネルモード ドライバーの特権の昇格の脆弱性 CWE-843
型の取り違え
CVE-2026-45600 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1954 7.8 重要
Local
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2012
Microsoft Windows 11 24h2
Microsoft Windows 10 21h2
Microsoft Wind…
UEFI セキュア ブートのセキュリティ機能バイパスの脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-45656 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1955 9.8 緊急
Network
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows 11 24h2
Microsoft Windows Server 2022
Microsoft Windows 11 23h2
Microsoft Wind…
Windows カーネルのリモートでコードが実行される脆弱性 CWE-122
CWE-416
CVE-2026-45657 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1956 6.8 警告
Physics
マイクロソフト Microsoft Windows 11 25h2
Microsoft Windows Server 2012
Microsoft Windows 11 24h2
Microsoft Windows 10 21h2
Microsoft Wind…
Windows BitLocker セキュリティ機能バイパスの脆弱性 CWE-284
CWE-noinfo
CVE-2026-45658 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1957 7.5 重要
Network
FreeSWITCH FreeSWITCH FreeSWITCHにおけるDTD の再帰的なエンティティ参照の不適切な制限に関する脆弱性 CWE-776
DTD の再帰的なエンティティ参照の不適切な制限
CVE-2026-45771 2026-06-11 16:23 2026-06-9 Show GitHub Exploit DB Packet Storm
1958 4.3 警告
Network
University at Buffalo Open XDMoD University at BuffaloのOpen XDMoDにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-45776 2026-06-11 16:23 2026-06-5 Show GitHub Exploit DB Packet Storm
1959 9.8 緊急
Network
University at Buffalo Open XDMoD University at BuffaloのOpen XDMoDにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-45777 2026-06-11 16:23 2026-06-5 Show GitHub Exploit DB Packet Storm
1960 5.4 警告
Network
University at Buffalo Open XDMoD University at BuffaloのOpen XDMoDにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45778 2026-06-11 16:23 2026-06-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
307021 - advantech advantech_webaccess Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-0241 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307022 - advantech advantech_webaccess GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors. CWE-287
Improper Authentication
CVE-2012-0240 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307023 - advantech advantech_webaccess uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request. CWE-287
Improper Authentication
CVE-2012-0239 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307024 - advantech advantech_webaccess Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-0238 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307025 - advantech advantech_webaccess Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-0237 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307026 - advantech advantech_webaccess Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security… CWE-200
Information Exposure
CVE-2012-0236 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307027 - advantech advantech_webaccess Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. CWE-352
 Origin Validation Error
CVE-2012-0235 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307028 - advantech advantech_webaccess SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL. CWE-89
SQL Injection
CVE-2012-0234 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307029 - advantech advantech_webaccess Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL. CWE-79
Cross-site Scripting
CVE-2012-0233 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm
307030 - ibm soliddb The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT state… NVD-CWE-noinfo
CVE-2012-0200 2024-11-21 10:34 2012-02-21 Show GitHub Exploit DB Packet Storm