Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219331 6.8 警告 Iptanus - WordPress 用 File Upload プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-5199 2014-08-14 17:14 2014-08-8 Show GitHub Exploit DB Packet Storm
219332 4.3 警告 Blackbam - WordPress 用 Improved user search in backend プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5196 2014-08-14 17:13 2014-08-8 Show GitHub Exploit DB Packet Storm
219333 4.9 警告 ゾール・メディカル - ZOLL 除細動器 X シリーズにおけるデバイスの設定を変更される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-7395 2014-08-14 17:08 2013-08-1 Show GitHub Exploit DB Packet Storm
219334 4.9 警告 ゾール・メディカル - ZOLL 除細動器の複数のシリーズにおけるデバイスの設定を変更される脆弱性 CWE-255
証明書・パスワード管理
CVE-2007-6756 2014-08-14 17:07 2007-05-1 Show GitHub Exploit DB Packet Storm
219335 4 警告 ヒューレット・パッカード - HP NonStop Safeguard Security Software におけるプログラムのアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2629 2014-08-14 16:12 2014-08-5 Show GitHub Exploit DB Packet Storm
219336 7.2 危険 IBM - IBM Security AppScan Source の Automation Server における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2014-3072 2014-08-14 15:59 2014-07-30 Show GitHub Exploit DB Packet Storm
219337 7.5 危険 MegaLab.it - MegaLab The Uploader の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-2944 2014-08-14 15:54 2011-07-28 Show GitHub Exploit DB Packet Storm
219338 6.8 警告 シトリックス・システムズ - Citrix Access Gateway Enterprise Edition Plug-in for Windows の nsepacom ActiveX コントロールの StartEpa メソッドにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2011-2593 2014-08-14 15:48 2011-07-19 Show GitHub Exploit DB Packet Storm
219339 4.3 警告 Brian Nez - Microcart におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4241 2014-08-14 15:42 2012-07-23 Show GitHub Exploit DB Packet Storm
219340 10 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR における ASLR 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0545 2014-08-14 14:46 2014-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 6.5 MEDIUM
Network
- - Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a cra… New CWE-20
 Improper Input Validation 
CVE-2026-11658 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
532 6.5 MEDIUM
Network
- - Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page… New CWE-20
 Improper Input Validation 
CVE-2026-11653 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
533 8.3 HIGH
Network
- - Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.… New CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-11640 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
534 8.8 HIGH
Network
- - Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exe… New CWE-78
CWE-77
OS Command 
Command Injection
CVE-2026-11572 2026-06-9 23:16 2026-06-9 Show GitHub Exploit DB Packet Storm
535 6.5 MEDIUM
Network
google chrome Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) Update CWE-693
 Protection Mechanism Failure
CVE-2026-11288 2026-06-9 22:59 2026-06-5 Show GitHub Exploit DB Packet Storm
536 6.5 MEDIUM
Network
google chrome Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) Update CWE-1300
CWE-203
 Improper Protection of Physical Side Channels
 Information Exposure Through Discrepancy
CVE-2026-11289 2026-06-9 22:58 2026-06-5 Show GitHub Exploit DB Packet Storm
537 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulne… New CWE-121
Stack-based Buffer Overflow
CVE-2026-36789 2026-06-9 22:57 2026-06-9 Show GitHub Exploit DB Packet Storm
538 6.5 MEDIUM
Network
- - OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account c… New CWE-348
 Use of Less Trusted Source
CVE-2020-37248 2026-06-9 22:57 2026-06-9 Show GitHub Exploit DB Packet Storm
539 7.5 HIGH
Network
- - Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types and presenting a set of parameters t… New CWE-122
Heap-based Buffer Overflow
CVE-2026-22164 2026-06-9 22:57 2026-06-9 Show GitHub Exploit DB Packet Storm
540 7.1 HIGH
Local
- - Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation. The product accidenta… New CWE-468
CVE-2026-34194 2026-06-9 22:57 2026-06-9 Show GitHub Exploit DB Packet Storm