Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228981 9.3 危険 キングソフト株式会社 - Kingsoft Spreadsheets 2012 におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-0723 2013-07-31 13:47 2013-07-29 Show GitHub Exploit DB Packet Storm
228982 5 警告 ヒューレット・パッカード
レッドハット
- 複数の Red Hat JBoss 製品の JBossWS Native におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2011-1483 2013-07-30 17:40 2011-04-4 Show GitHub Exploit DB Packet Storm
228983 4.7 警告 Linux - Linux Kernel のブリッジのマルチキャストの実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-4129 2013-07-30 17:21 2013-07-7 Show GitHub Exploit DB Packet Storm
228984 4.7 警告 Linux - Linux Kernel の drivers/vhost/net.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-4127 2013-07-30 17:21 2013-07-9 Show GitHub Exploit DB Packet Storm
228985 6.4 警告 FreeBSD - FreeBSD のカーネルにおける NFS ファイルシステムのファイルパーミッションを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4851 2013-07-30 16:42 2013-07-26 Show GitHub Exploit DB Packet Storm
228986 6.5 警告 IBM - IBM Tivoli Remote Control のサーバコンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-3033 2013-07-30 16:34 2013-07-29 Show GitHub Exploit DB Packet Storm
228987 4.3 警告 Moodle
Yahoo!
- Moodle などの製品で使用される Yahoo! YUI の Uploader コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4942 2013-07-30 16:22 2013-07-15 Show GitHub Exploit DB Packet Storm
228988 4.3 警告 Moodle
Yahoo!
- Moodle などの製品で使用される Yahoo! YUI の Uploader コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4941 2013-07-30 16:21 2013-07-15 Show GitHub Exploit DB Packet Storm
228989 4.3 警告 Moodle
Yahoo!
- Moodle などの製品で使用される Yahoo! YUI の IO Utility コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4940 2013-07-30 16:20 2013-07-15 Show GitHub Exploit DB Packet Storm
228990 4.3 警告 Moodle
Yahoo!
- Moodle などの製品で使用される Yahoo! YUI の IO Utility コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4939 2013-07-30 16:19 2013-07-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3991 4.3 MEDIUM
Network
- - A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite sys… CWE-749
 Exposed Dangerous Method or Function
CVE-2026-7516 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3992 7.0 HIGH
Local
- - A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. CWE-290
 Authentication Bypass by Spoofing
CVE-2026-6090 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3993 7.1 HIGH
Network
- - libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-53689 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3994 9.6 CRITICAL
Network
- - A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-53470 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3995 9.1 CRITICAL
Network
- - A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. T… CWE-306
Missing Authentication for Critical Function
CVE-2026-53469 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3996 9.9 CRITICAL
Network
- - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/rout… CWE-639
CWE-862
CWE-863
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
 Incorrect Authorization
CVE-2026-45552 2026-06-11 00:16 2026-06-11 Show GitHub Exploit DB Packet Storm
3997 9.8 CRITICAL
Network
- - DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. CWE-78
OS Command 
CVE-2026-38615 2026-06-11 00:16 2026-06-10 Show GitHub Exploit DB Packet Storm
3998 9.8 CRITICAL
Network
- - A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-36721 2026-06-11 00:16 2026-06-10 Show GitHub Exploit DB Packet Storm
3999 7.5 HIGH
Network
- - An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via e… CWE-200
Information Exposure
CVE-2026-36719 2026-06-11 00:16 2026-06-10 Show GitHub Exploit DB Packet Storm
4000 8.4 HIGH
Local
- - Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-24067 2026-06-11 00:16 2026-06-10 Show GitHub Exploit DB Packet Storm