Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211201 7.5 危険 X2Engine - X2Engine X2CRM の protected/components/filters/FileUploadsFilter.php の FileUploadsFilter クラスにおける任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2015-5074 2015-10-1 17:43 2015-07-13 Show GitHub Exploit DB Packet Storm
211202 4 警告 TIBCO Software - 複数の TIBCO 製品における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-5711 2015-10-1 17:37 2015-09-29 Show GitHub Exploit DB Packet Storm
211203 4.3 警告 Splunk - Splunk Enterprise および Splunk Light の Splunk Web におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-7604 2015-10-1 17:31 2015-09-14 Show GitHub Exploit DB Packet Storm
211204 4 警告 ヒューレット・パッカード - HP Integrated Lights-Out 3 および Integrated Lights-Out 4 のファームウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2015-5435 2015-10-1 17:25 2015-09-23 Show GitHub Exploit DB Packet Storm
211205 4.6 警告 ヒューレット・パッカード - HP Software Update における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2015-5442 2015-10-1 17:25 2015-09-18 Show GitHub Exploit DB Packet Storm
211206 5 警告 The FreeImage Project - FreeImage の PluginPCX.cpp における整数アンダーフローの脆弱性 CWE-189
数値処理の問題
CVE-2015-0852 2015-10-1 17:07 2015-08-28 Show GitHub Exploit DB Packet Storm
211207 4.3 警告 CodePeople - WordPress 用 Appointment Booking Calendar プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-7320 2015-10-1 16:57 2015-09-26 Show GitHub Exploit DB Packet Storm
211208 7.5 危険 CodePeople - WordPress 用 Appointment Booking Calendar プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-7319 2015-10-1 16:57 2015-09-26 Show GitHub Exploit DB Packet Storm
211209 4.3 警告 Open-Xchange - Open-Xchange Server 6 および OX App Suite の Front End の印刷コンテンツ用のダイアログにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-5375 2015-10-1 16:53 2015-07-22 Show GitHub Exploit DB Packet Storm
211210 6.8 警告 IPython development team
Project Jupyter
- IPython Notebook および Jupyter Notebook のエディタにおける任意の JavaScript コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2015-7337 2015-10-1 16:47 2015-09-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
621 6.7 MEDIUM
Local
- - A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges … CWE-122
Heap-based Buffer Overflow
CVE-2026-48914 2026-06-13 01:06 2026-06-12 Show GitHub Exploit DB Packet Storm
622 - - - A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remedia… CWE-325
 Missing Required Cryptographic Step
CVE-2026-9266 2026-06-13 01:06 2026-06-12 Show GitHub Exploit DB Packet Storm
623 8.7 HIGH
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's… CWE-693
 Protection Mechanism Failure
CVE-2026-47135 2026-06-13 01:03 2026-06-13 Show GitHub Exploit DB Packet Storm
624 10.0 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: t… CWE-913
 Improper Control of Dynamically-Managed Code Resources
CVE-2026-47137 2026-06-13 01:03 2026-06-13 Show GitHub Exploit DB Packet Storm
625 8.6 HIGH
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target o… CWE-693
 Protection Mechanism Failure
CVE-2026-47209 2026-06-13 01:03 2026-06-13 Show GitHub Exploit DB Packet Storm
626 8.0 HIGH
Network
microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CWE-285
Improper Authorization
CVE-2026-47298 2026-06-13 01:00 2026-06-10 Show GitHub Exploit DB Packet Storm
627 8.8 HIGH
Network
- - The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operat… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-12059 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
628 6.5 MEDIUM
Network
- - Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim … CWE-749
 Exposed Dangerous Method or Function
CVE-2026-12060 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
629 4.9 MEDIUM
Network
- - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended director… CWE-22
Path Traversal
CVE-2026-11844 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
630 7.2 HIGH
Network
- - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute … CWE-78
OS Command 
CVE-2026-11845 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm