Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232021 7.5 危険 xcms - XCMS の cpie.php における静的コードを直接挿入する攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-6652 2012-12-20 18:34 2008-01-4 Show GitHub Exploit DB Packet Storm
232022 5 警告 sanybee gallery - SanyBee Gallery の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6648 2012-12-20 18:34 2008-01-4 Show GitHub Exploit DB Packet Storm
232023 7.5 危険 W-Agora - w-Agora の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6647 2012-12-20 18:34 2008-01-4 Show GitHub Exploit DB Packet Storm
232024 6.8 警告 xml2owl - xml2owl の showCode.php における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-6632 2012-12-20 18:34 2008-01-3 Show GitHub Exploit DB Packet Storm
232025 6.8 警告 pnphpbb - PNphpBB2 の printview.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6624 2012-12-20 18:34 2008-01-3 Show GitHub Exploit DB Packet Storm
232026 5 警告 zeuscms - ZeusCMS における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6623 2012-12-20 18:34 2008-01-3 Show GitHub Exploit DB Packet Storm
232027 7.5 危険 zeuscms - ZeusCMS の security.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6622 2012-12-20 18:34 2008-01-3 Show GitHub Exploit DB Packet Storm
232028 4.3 警告 simpleforum - SimpleForum の simpleforum.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6616 2012-12-20 18:34 2008-01-3 Show GitHub Exploit DB Packet Storm
232029 5.8 警告 skyfex - SkyFex Client の SkyFexClient.ocx におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6605 2012-12-20 18:34 2007-12-31 Show GitHub Exploit DB Packet Storm
232030 5 警告 xcms - XCMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6604 2012-12-20 18:34 2007-12-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
321 7.8 HIGH
Local
- - Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. New CWE-284
Improper Access Control
CVE-2026-42829 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
322 7.8 HIGH
Local
- - Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. New CWE-126
 Buffer Over-read
CVE-2026-42828 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
323 - - - Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Imp… New CWE-125
Out-of-bounds Read
CVE-2026-42771 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
324 - - - Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which present… New CWE-325
 Missing Required Cryptographic Step
CVE-2026-42770 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
325 - - - Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation inef… New CWE-295
Improper Certificate Validation 
CVE-2026-42769 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
326 - - - Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/… New CWE-514
CVE-2026-42768 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
327 - - - Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference ca… New CWE-476
 NULL Pointer Dereference
CVE-2026-42767 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
328 - - - Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application … New CWE-476
 NULL Pointer Dereference
CVE-2026-42766 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
329 - - - Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a … New CWE-476
 NULL Pointer Dereference
CVE-2026-42765 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
330 - - - Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer … New CWE-476
 NULL Pointer Dereference
CVE-2026-42764 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm