Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231591 5 警告 Linux - Linux Kernel の net/ipv6/reassembly.c におけるネットワーク制限を回避される脆弱性 CWE-noinfo
情報不足
CVE-2012-4444 2012-12-25 14:25 2012-10-20 Show GitHub Exploit DB Packet Storm
231592 5.8 警告 Fetchmail Project - Fetchmail におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2012-3482 2012-12-25 14:11 2012-08-13 Show GitHub Exploit DB Packet Storm
231593 6.8 警告 オラクル - 複数の Oracle 製品で使用される DataDirect ODBC ドライバにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-3133 2012-12-25 14:09 2012-08-23 Show GitHub Exploit DB Packet Storm
231594 10 危険 オラクル - Oracle Hyperion Financial Management の TList 6 ActiveX コントロールにおける任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2012-1714 2012-12-25 14:08 2012-06-26 Show GitHub Exploit DB Packet Storm
231595 10 危険 オラクル - Oracle Sun GlassFish Web Space Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-1712 2012-12-25 14:07 2012-06-26 Show GitHub Exploit DB Packet Storm
231596 7.5 危険 MySQL AB
オラクル
- MySQL で使用される yaSSL におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0882 2012-12-25 13:52 2012-12-4 Show GitHub Exploit DB Packet Storm
231597 4.3 警告 The Perl Foundation - Perl の File::Glob モジュールにおけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-Other
その他
CVE-2011-2728 2012-12-25 13:45 2012-12-21 Show GitHub Exploit DB Packet Storm
231598 1.9 注意 GNOME Project - GNOME Display Manager における権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-2387 2012-12-25 13:44 2010-06-2 Show GitHub Exploit DB Packet Storm
231599 4 警告 レッドハット
VMware
Samba Project
- Samba Web Administration Tool におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-2522 2012-12-21 17:34 2011-07-26 Show GitHub Exploit DB Packet Storm
231600 4.4 警告 ターボリナックス
VMware
レッドハット
Samba Project
- Samba の smbfs における権限を取得される脆弱性 CWE-59
リンク解釈の問題
CVE-2010-0787 2012-12-21 16:50 2010-02-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2111 9.1 CRITICAL
Network
- - Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using … CWE-338
CWE-340
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
 Generation of Predictable Numbers or Identifiers
CVE-2026-9733 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
2112 5.3 MEDIUM
Network
- - IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized request… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7253 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
2113 8.8 HIGH
Network
misp-project misp MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affe… CWE-639
CWE-862
CWE-863
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
 Incorrect Authorization
CVE-2026-56424 2026-06-24 00:16 2026-06-22 Show GitHub Exploit DB Packet Storm
2114 8.8 HIGH
Network
misp-project misp MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level perm… CWE-862
 Missing Authorization
CVE-2026-56423 2026-06-24 00:16 2026-06-22 Show GitHub Exploit DB Packet Storm
2115 8.8 HIGH
Network
- - phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin user… CWE-862
 Missing Authorization
CVE-2026-56396 2026-06-24 00:16 2026-06-21 Show GitHub Exploit DB Packet Storm
2116 4.8 MEDIUM
Network
- - Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row h… CWE-79
Cross-site Scripting
CVE-2026-56383 2026-06-24 00:16 2026-06-21 Show GitHub Exploit DB Packet Storm
2117 5.3 MEDIUM
Network
- - Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_binding… CWE-306
Missing Authentication for Critical Function
CVE-2026-56321 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
2118 7.1 HIGH
Network
- - Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted b… CWE-672
 Operation on a Resource after Expiration or Release
CVE-2026-56314 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
2119 5.3 MEDIUM
Network
- - Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers c… CWE-306
Missing Authentication for Critical Function
CVE-2026-56299 2026-06-24 00:16 2026-06-21 Show GitHub Exploit DB Packet Storm
2120 8.6 HIGH
Network
- - Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenti… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-56266 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm