Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231431 2.1 注意 サイバートラスト株式会社
VMware
Linux
レッドハット
- Linux kernel の sk_run_filter 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-4158 2012-12-25 17:56 2010-12-30 Show GitHub Exploit DB Packet Storm
231432 9.3 危険 サムスン
Meizu
- Samsung GALAXY および Meizu MX など Android デバイスにおける任意の物理メモリを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6422 2012-12-25 17:53 2012-12-18 Show GitHub Exploit DB Packet Storm
231433 7.2 危険 シマンテック - Symantec Endpoint Protection の管理コンソールにおける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4348 2012-12-25 17:50 2012-12-10 Show GitHub Exploit DB Packet Storm
231434 1.2 注意 Linux - Linux Kernel の rio_ioctl 関数における Ethernet アダプタへデータを書き込まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2313 2012-12-25 17:46 2012-06-13 Show GitHub Exploit DB Packet Storm
231435 7.1 危険 Linux - Linux Kernel の fs/ext4/super.c におけるファイルシステムグループデータの不整合を誘発される脆弱性 CWE-189
数値処理の問題
CVE-2012-2100 2012-12-25 17:44 2012-07-3 Show GitHub Exploit DB Packet Storm
231436 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 および 10 における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2012-4782 2012-12-25 17:11 2012-12-11 Show GitHub Exploit DB Packet Storm
231437 9.3 危険 マイクロソフト - Microsoft Windows における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-4774 2012-12-25 17:08 2012-12-11 Show GitHub Exploit DB Packet Storm
231438 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品のカーネルモードドライバにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-2556 2012-12-25 17:05 2012-12-11 Show GitHub Exploit DB Packet Storm
231439 10 危険 Wansview
ShenZhen Foscam Intelligent Technology
- 複数のネットワークカメラに認証回避の脆弱性 CWE-287
不適切な認証
CVE-2012-3002 2012-12-25 16:44 2012-10-11 Show GitHub Exploit DB Packet Storm
231440 10 危険 Carlo Gavazzi - Carlo Gavazzi EOS-Box のファームウェアにおける管理アクセス権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2012-6428 2012-12-25 16:37 2012-12-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2331 7.1 HIGH
Network
- - Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Att… CWE-89
SQL Injection
CVE-2019-25759 2026-06-23 03:39 2026-06-20 Show GitHub Exploit DB Packet Storm
2332 6.5 MEDIUM
Network
- - The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' b… - CVE-2026-9822 2026-06-23 03:38 2026-06-19 Show GitHub Exploit DB Packet Storm
2333 9.8 CRITICAL
Network
- - WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functi… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2019-25763 2026-06-23 03:38 2026-06-20 Show GitHub Exploit DB Packet Storm
2334 5.3 MEDIUM
Network
- - The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token… - CVE-2026-10530 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2335 6.1 MEDIUM
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… - CVE-2026-4110 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2336 7.1 HIGH
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… CWE-79
Cross-site Scripting
CVE-2026-4259 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2337 7.1 HIGH
Network
- - The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator CWE-79
Cross-site Scripting
CVE-2026-6858 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2338 5.3 MEDIUM
Network
- - The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such a… CWE-862
 Missing Authorization
CVE-2026-7859 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2339 8.8 HIGH
Network
- - The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a cus… CWE-269
 Improper Privilege Management
CVE-2026-8157 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2340 8.2 HIGH
Network
- - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter… CWE-89
SQL Injection
CVE-2017-20255 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm