Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222671 4.3 警告 Quagga - Quagga の bgp_attr.c の bgp_attr_unknown 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-6051 2013-12-17 17:43 2013-11-26 Show GitHub Exploit DB Packet Storm
222672 6.8 警告 Devscripts Devel Team - devscripts の scripts/uscan.pl の get_main_source_dir 関数における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-7050 2013-12-17 17:14 2013-12-11 Show GitHub Exploit DB Packet Storm
222673 7.5 危険 SAP - SAP EMR Unwired における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7096 2013-12-17 17:12 2013-11-20 Show GitHub Exploit DB Packet Storm
222674 10 危険 SAP - SAP Customer Relationship Management の XML パーサにおける脆弱性 CWE-noinfo
情報不足
CVE-2013-7095 2013-12-17 17:12 2013-11-20 Show GitHub Exploit DB Packet Storm
222675 7.5 危険 SAP - SAP NetWeaver の RSDDCVER_COUNT_TAB_COLS 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7094 2013-12-17 17:11 2013-11-20 Show GitHub Exploit DB Packet Storm
222676 5 警告 SAP - SAP Network Interface Router における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-7093 2013-12-17 17:10 2013-11-20 Show GitHub Exploit DB Packet Storm
222677 5 警告 RockMongo - RockMongo におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-5107 2013-12-17 16:54 2013-08-16 Show GitHub Exploit DB Packet Storm
222678 5 警告 Zabbix - Zabbix の user.login 関数における LDAP 設定を上書きされる脆弱性 CWE-287
不適切な認証
CVE-2013-1364 2013-12-17 16:47 2013-01-4 Show GitHub Exploit DB Packet Storm
222679 4.3 警告 MediaWiki - MediaWiki の CleanChanges 拡張機能における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-4569 2013-12-17 16:42 2013-11-14 Show GitHub Exploit DB Packet Storm
222680 4.3 警告 MediaWiki - MediaWiki の Sanitizer::checkCss におけるクロスサイトスクリプティングの脆弱性 CWE-Other
その他
CVE-2013-4568 2013-12-17 16:41 2013-11-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
751 9.8 CRITICAL
Network
joomla joomla\! An improper validation of user-supplied input leads to a local file inclusion vulnerability. New CWE-22
Path Traversal
CVE-2026-40383 2026-05-27 21:24 2026-05-27 Show GitHub Exploit DB Packet Storm
752 7.5 HIGH
Network
microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. New CWE-269
 Improper Privilege Management
CVE-2026-23663 2026-05-27 21:16 2026-05-23 Show GitHub Exploit DB Packet Storm
753 10.0 CRITICAL
Network
microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. New CWE-346
 Origin Validation Error
CVE-2026-42901 2026-05-27 21:13 2026-05-23 Show GitHub Exploit DB Packet Storm
754 - - - The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. New CWE-284
Improper Access Control
CVE-2026-48906 2026-05-27 20:16 2026-05-27 Show GitHub Exploit DB Packet Storm
755 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11… New CWE-89
SQL Injection
CVE-2026-8054 2026-05-27 18:16 2026-05-27 Show GitHub Exploit DB Packet Storm
756 9.1 CRITICAL
Network
- - Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo… New CWE-284
Improper Access Control
CVE-2026-49002 2026-05-27 18:16 2026-05-27 Show GitHub Exploit DB Packet Storm
757 5.3 MEDIUM
Network
- - Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe… New CWE-352
 Origin Validation Error
CVE-2026-49001 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
758 7.0 HIGH
Network
- - An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag… New CWE-310
Cryptographic Issues
CVE-2026-49000 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
759 5.7 MEDIUM
Network
- - Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo… New CWE-79
Cross-site Scripting
CVE-2026-48999 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
760 - - - IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/… New CWE-755
 Improper Handling of Exceptional Conditions
CVE-2026-48961 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm