Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230321 10 危険 3S-Smart Software Solutions - 3S CODESYS Gateway-Server における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-4707 2013-02-27 15:06 2013-02-19 Show GitHub Exploit DB Packet Storm
230322 7.8 危険 3S-Smart Software Solutions - 3S CODESYS Gateway-Server における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2012-4706 2013-02-27 15:05 2013-02-19 Show GitHub Exploit DB Packet Storm
230323 10 危険 3S-Smart Software Solutions - 3S CODESYS Gateway-Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-4705 2013-02-27 15:02 2013-02-19 Show GitHub Exploit DB Packet Storm
230324 10 危険 3S-Smart Software Solutions - 3S CODESYS Gateway-Server における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4704 2013-02-27 15:01 2013-02-19 Show GitHub Exploit DB Packet Storm
230325 6.8 警告 Honeywell International Inc. - 複数の Honeywell 製品の HscRemoteDeploy.dll における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-0108 2013-02-27 14:39 2013-02-24 Show GitHub Exploit DB Packet Storm
230326 10 危険 Novell - Novell GroupWise のクライアントにおける任意のコードを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2013-0804 2013-02-27 09:54 2013-01-23 Show GitHub Exploit DB Packet Storm
230327 9.3 危険 Novell - Novell GroupWise のクライアント内の gwcls1.dll における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-0439 2013-02-27 09:54 2013-01-23 Show GitHub Exploit DB Packet Storm
230328 10 危険 BigAntSoft - BigAntSoft BigAnt IM Message Server におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-6275 2013-02-26 16:03 2013-02-24 Show GitHub Exploit DB Packet Storm
230329 9.7 危険 BigAntSoft - BigAntSoft BigAnt IM Message Server における任意のファイルを作成される脆弱性 CWE-287
不適切な認証
CVE-2012-6274 2013-02-26 16:03 2013-02-24 Show GitHub Exploit DB Packet Storm
230330 7.5 危険 BigAntSoft - BigAntSoft BigAnt IM Message Server における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6273 2013-02-26 16:02 2013-02-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1631 6.5 MEDIUM
Local
libexpat_project libexpat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. CWE-190
 Integer Overflow or Wraparound
CVE-2026-56409 2026-06-24 01:21 2026-06-22 Show GitHub Exploit DB Packet Storm
1632 6.9 MEDIUM
Local
libexpat_project libexpat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. CWE-190
 Integer Overflow or Wraparound
CVE-2026-56410 2026-06-24 01:18 2026-06-22 Show GitHub Exploit DB Packet Storm
1633 7.4 HIGH
Local
- - pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor. CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-56815 2026-06-24 01:17 2026-06-24 Show GitHub Exploit DB Packet Storm
1634 6.5 MEDIUM
Network
- - Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simple… CWE-611
XXE
CVE-2026-56701 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1635 7.2 HIGH
Network
misp-project misp MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated… CWE-94
Code Injection
CVE-2026-56446 2026-06-24 01:17 2026-06-22 Show GitHub Exploit DB Packet Storm
1636 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and deter… CWE-200
Information Exposure
CVE-2026-56323 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1637 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allow… CWE-200
Information Exposure
CVE-2026-56322 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1638 8.1 HIGH
Network
- - Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enable… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-56243 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1639 8.2 HIGH
Network
- - Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSo… CWE-862
 Missing Authorization
CVE-2026-56104 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1640 7.5 HIGH
Network
astro astro Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. T… CWE-20
CWE-918
 Improper Input Validation 
Server-Side Request Forgery (SSRF) 
CVE-2026-54299 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm