Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223691 4.3 警告 マイクロソフト - 複数の Microsoft 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1754 2014-05-15 14:21 2014-05-13 Show GitHub Exploit DB Packet Storm
223692 9 危険 マイクロソフト - 複数の Microsoft 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-0251 2014-05-15 14:21 2014-05-13 Show GitHub Exploit DB Packet Storm
223693 5 警告 Haxx
アップル
Canonical
- cURL および libcurl の cookie.c における Cookie を盗まれる脆弱性 CWE-200
情報漏えい
CVE-2013-1944 2014-05-14 18:45 2013-04-12 Show GitHub Exploit DB Packet Storm
223694 4.3 警告 FreeType Project - FreeType の _bdf_parse_glyphs 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-5670 2014-05-14 18:44 2012-12-20 Show GitHub Exploit DB Packet Storm
223695 4.3 警告 FreeType Project - FreeType の _bdf_parse_glyphs 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-5669 2014-05-14 18:43 2012-12-20 Show GitHub Exploit DB Packet Storm
223696 4.3 警告 FreeType Project - FreeType におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-5668 2014-05-14 18:43 2012-12-20 Show GitHub Exploit DB Packet Storm
223697 4.6 警告 サイバートラスト株式会社
XScreenSaver project
レッドハット
- XScreenSaver のクラッシュによりスクリーンロックが解除される問題 CWE-287
不適切な認証
CVE-2007-1859 2014-05-14 18:41 2007-05-3 Show GitHub Exploit DB Packet Storm
223698 5 警告 VMware - VMware SpringSource Grails におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1833 2014-05-14 18:40 2012-08-13 Show GitHub Exploit DB Packet Storm
223699 5 警告 Secure Locate - slocate における非公開ファイルの名前を取得される脆弱性 - CVE-2007-0227 2014-05-14 18:39 2007-01-12 Show GitHub Exploit DB Packet Storm
223700 5 警告 Samba Project - Samba におけるアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-4496 2014-05-14 18:36 2013-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1611 8.8 HIGH
Network
- - Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope res… CWE-863
 Incorrect Authorization
CVE-2026-56232 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1612 9.1 CRITICAL
Network
- - Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails to validate that keys are se… CWE-287
Improper Authentication
CVE-2026-56237 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1613 7.1 HIGH
Network
- - Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the web… CWE-200
Information Exposure
CVE-2026-56244 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1614 8.2 HIGH
Network
- - Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to insert arbitrary build-ti… CWE-269
 Improper Privilege Management
CVE-2026-56245 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1615 7.1 HIGH
Network
- - Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do … CWE-602
 Client-Side Enforcement of Server-Side Security
CVE-2026-56256 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1616 6.5 MEDIUM
Network
- - Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. Remote attackers ca… CWE-284
Improper Access Control
CVE-2026-56302 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1617 5.3 MEDIUM
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/… CWE-200
Information Exposure
CVE-2026-56337 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1618 5.3 MEDIUM
Network
- - Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authen… CWE-703
 Improper Check or Handling of Exceptional Conditions
CVE-2026-56338 2026-06-25 23:03 2026-06-24 Show GitHub Exploit DB Packet Storm
1619 10.0 CRITICAL
Network
- - GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP me… CWE-121
Stack-based Buffer Overflow
CVE-2026-12485 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm
1620 9.1 CRITICAL
Network
- - Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker… CWE-78
OS Command 
CVE-2026-12486 2026-06-25 23:02 2026-06-24 Show GitHub Exploit DB Packet Storm