Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224851 5.8 警告 MediaWiki - MediaWiki の includes/User.php におけるアクセス権を取得される脆弱性 CWE-362
競合状態
CVE-2014-2243 2014-03-4 17:06 2014-02-28 Show GitHub Exploit DB Packet Storm
224852 4.3 警告 MediaWiki - MediaWiki の includes/upload/UploadBase.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2242 2014-03-4 17:06 2014-02-28 Show GitHub Exploit DB Packet Storm
224853 4.3 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の Business Voice Services Manager のページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2104 2014-03-4 17:00 2014-02-28 Show GitHub Exploit DB Packet Storm
224854 7.9 危険 ブルーコートシステムズ - Blue Coat ProxySG に脆弱性 CWE-264
CWE-Other
CVE-2014-2033 2014-03-4 16:58 2014-02-28 Show GitHub Exploit DB Packet Storm
224855 9.3 危険 SAS - Base SAS のクライアントアプリケーションにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-2262 2014-03-4 16:38 2014-01-17 Show GitHub Exploit DB Packet Storm
224856 2.6 注意 Debian
Canonical
- apt の methods/https.cc におけるリポジトリの認証情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-3634 2014-03-4 16:18 2011-02-8 Show GitHub Exploit DB Packet Storm
224857 10 危険 IBM - IBM Rational コラボレーティブ・ライフサイクル・マネージメントにおける任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2014-0862 2014-03-4 15:57 2014-02-28 Show GitHub Exploit DB Packet Storm
224858 4.3 警告 IBM - IBM WebSphere MQ の WMQ Telemetry におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-4054 2014-03-4 15:57 2013-06-7 Show GitHub Exploit DB Packet Storm
224859 6.8 警告 FFmpeg - FFmpeg の libavcodec/msrle.c の msrle_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2014-2099 2014-03-4 15:55 2014-02-17 Show GitHub Exploit DB Packet Storm
224860 6.8 警告 FFmpeg - FFmpeg の libavcodec/wmalosslessdec.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2014-2098 2014-03-4 15:55 2014-02-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
761 7.5 HIGH
Network
- - Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. New CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-54841 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
762 8.5 HIGH
Network
- - Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. New CWE-89
SQL Injection
CVE-2026-54838 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
763 9.9 CRITICAL
Network
- - Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. New CWE-94
Code Injection
CVE-2026-54823 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
764 8.5 HIGH
Network
- - Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. New CWE-89
SQL Injection
CVE-2026-54822 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
765 9.9 CRITICAL
Network
- - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via … New CWE-79
CWE-1188
Cross-site Scripting
 Insecure Default Initialization of Resource
CVE-2026-54067 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
766 4.0 MEDIUM
Network
- - Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghos… New CWE-367
CWE-918
 Time-of-check Time-of-use (TOCTOU) Race Condition
Server-Side Request Forgery (SSRF) 
CVE-2026-53945 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
767 - - - Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v… New CWE-200
Information Exposure
CVE-2026-52815 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
768 - - - Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evalu… New CWE-284
Improper Access Control
CVE-2026-52810 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
769 7.1 HIGH
Network
- - Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:o… New CWE-269
CWE-863
 Improper Privilege Management
 Incorrect Authorization
CVE-2026-52808 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm
770 - - - Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to &lt; etc. This prevent… New CWE-79
Cross-site Scripting
CVE-2026-52807 2026-06-26 01:16 2026-06-25 Show GitHub Exploit DB Packet Storm