Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216221 3.5 注意 Absolut Engine - Absolut Engine の administrative バックエンドの admin/managerrelated.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9434 2015-01-7 19:09 2014-12-30 Show GitHub Exploit DB Packet Storm
216222 4 警告 Vtiger - Vtiger CRM の kcfinder/browse.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-1222 2015-01-7 17:50 2014-03-11 Show GitHub Exploit DB Packet Storm
216223 6.2 警告 (複数のベンダ) - 複数の UEFI システムにおいて EFI S3 Resume Boot Path で使われる boot script が適切に保護されていない問題 - CVE-2014-8274 2015-01-7 17:05 2015-01-5 Show GitHub Exploit DB Packet Storm
216224 6.2 警告 (複数のベンダ) - UEFI EDK1 にバッファオーバーフローの脆弱性 - CVE-2014-8271 2015-01-7 17:04 2015-01-5 Show GitHub Exploit DB Packet Storm
216225 6 警告 (複数のベンダ) - Intel BIOS ロッキングメカニズムに競合状態の脆弱性 CWE-362
競合状態
CVE-2014-8273 2015-01-7 16:46 2015-01-5 Show GitHub Exploit DB Packet Storm
216226 6.8 警告 Zaunz GmbH - CosmoShop の cgi-bin/admin/setup_edit.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-5306 2015-01-7 16:23 2011-03-10 Show GitHub Exploit DB Packet Storm
216227 4.3 警告 Zaunz GmbH - CosmoShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5305 2015-01-7 16:23 2011-03-10 Show GitHub Exploit DB Packet Storm
216228 6.8 警告 poMMo - poMMo Aardvark の admin/setup/config/users.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-5300 2015-01-7 15:57 2011-05-10 Show GitHub Exploit DB Packet Storm
216229 4.3 警告 poMMo - poMMo Aardvark におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5299 2015-01-7 15:56 2011-04-26 Show GitHub Exploit DB Packet Storm
216230 4.3 警告 Spitfire - Spitfire CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5303 2015-01-7 15:43 2011-03-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
381 8.0 HIGH
Network
microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Update CWE-285
Improper Authorization
CVE-2026-47298 2026-06-13 01:00 2026-06-10 Show GitHub Exploit DB Packet Storm
382 8.8 HIGH
Network
- - The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operat… New CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-12059 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
383 6.5 MEDIUM
Network
- - Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim … New CWE-749
 Exposed Dangerous Method or Function
CVE-2026-12060 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
384 4.9 MEDIUM
Network
- - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended director… New CWE-22
Path Traversal
CVE-2026-11844 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
385 7.2 HIGH
Network
- - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute … New CWE-78
OS Command 
CVE-2026-11845 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
386 8.1 HIGH
Network
- - The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to del… New CWE-22
Path Traversal
CVE-2026-11846 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
387 4.3 MEDIUM
Network
- - The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerability to create direc… New CWE-22
Path Traversal
CVE-2026-11847 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
388 5.3 MEDIUM
Network
- - The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain par… New CWE-306
Missing Authentication for Critical Function
CVE-2026-11848 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
389 9.8 CRITICAL
Network
- - The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain adminis… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-11849 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm
390 - - - MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified b… New CWE-427
 Uncontrolled Search Path Element
CVE-2026-11879 2026-06-13 01:00 2026-06-12 Show GitHub Exploit DB Packet Storm