Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 6:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224041 4.3 警告 Feng Office - Feng Office におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5744 2013-10-30 18:02 2013-10-9 Show GitHub Exploit DB Packet Storm
224042 4.6 警告 Linux - Linux Kernel の fs/xfs/xfs_buf.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1819 2013-10-30 17:54 2013-02-3 Show GitHub Exploit DB Packet Storm
224043 4.3 警告 CA Technologies - CA SiteMinder および SiteMinder Web エージェントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5968 2013-10-30 17:51 2013-10-24 Show GitHub Exploit DB Packet Storm
224044 4.3 警告 Ingo Renner - TYPO3 用 Apache Solr for TYPO3 エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6289 2013-10-30 17:27 2013-09-25 Show GitHub Exploit DB Packet Storm
224045 10 危険 Ingo Renner - TYPO3 用 Apache Solr for TYPO3 エクステンションにおける脆弱性 CWE-noinfo
情報不足
CVE-2013-6288 2013-10-30 17:24 2013-09-25 Show GitHub Exploit DB Packet Storm
224046 4.3 警告 Novell - Libzypp の RPM GPG 鍵のインポートおよび処理機能におけるリポジトリが署名されたと信じさせる脆弱性 CWE-310
暗号の問題
CVE-2013-3704 2013-10-30 16:55 2013-09-12 Show GitHub Exploit DB Packet Storm
224047 6.8 警告 OpenText - OpenText/IXOS ECM for SAP NetWeaver における任意の ABAP コードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-3243 2013-10-30 16:37 2013-04-24 Show GitHub Exploit DB Packet Storm
224048 6.8 警告 KTH - WaveSurfer で使用される The Snack Sound Toolkit におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-6303 2013-10-30 16:25 2013-09-11 Show GitHub Exploit DB Packet Storm
224049 6.8 警告 Aircrack-ng
Gentoo Linux
- Aircrack-ng におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1159 2013-10-30 16:15 2010-04-24 Show GitHub Exploit DB Packet Storm
224050 3.3 注意 レッドハット - Red Hat JBoss Enterprise Portal Platform のデフォルト設定における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2013-2102 2013-10-30 15:41 2013-10-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
91 9.1 CRITICAL
Network
- - In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnReques… Update - CVE-2026-9098 2026-06-3 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
92 9.8 CRITICAL
Network
- - Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and pa… Update - CVE-2026-9097 2026-06-3 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
93 7.5 HIGH
Network
- - Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.War… Update - CVE-2026-9096 2026-06-3 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
94 9.8 CRITICAL
Network
- - Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does … Update - CVE-2026-9094 2026-06-3 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
95 9.8 CRITICAL
Network
- - In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never… Update - CVE-2026-9093 2026-06-3 02:16 2026-05-29 Show GitHub Exploit DB Packet Storm
96 5.9 MEDIUM
Network
ibm websphere_application_server IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting … Update CWE-362
Race Condition
CVE-2026-5516 2026-06-3 02:16 2026-05-27 Show GitHub Exploit DB Packet Storm
97 5.5 MEDIUM
Local
ibm app_connect_enterprise IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. Update CWE-922
CWE-532
 Insecure Storage of Sensitive Information
 Inclusion of Sensitive Information in Log Files
CVE-2026-5515 2026-06-3 02:16 2026-05-27 Show GitHub Exploit DB Packet Storm
98 3.7 LOW
Network
- - A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive informat… New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-5419 2026-06-3 02:16 2026-06-2 Show GitHub Exploit DB Packet Storm
99 8.8 HIGH
Network
- - A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in … New CWE-538
 File and Directory Information Exposure
CVE-2026-49298 2026-06-3 02:16 2026-06-1 Show GitHub Exploit DB Packet Storm
100 5.9 MEDIUM
Network
- - Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_s… New CWE-295
Improper Certificate Validation 
CVE-2026-49267 2026-06-3 02:16 2026-06-1 Show GitHub Exploit DB Packet Storm