Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 12:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240191 4.3 警告 JoomlaTune - Joomla! 用の proofreader コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4157 2012-09-25 17:38 2009-12-2 Show GitHub Exploit DB Packet Storm
240192 7.5 危険 IBM - IBM WebSphere Portal の XMLAccess コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-4153 2012-09-25 17:38 2009-07-15 Show GitHub Exploit DB Packet Storm
240193 4.3 警告 IBM - IBM WebSphere Portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4152 2012-09-25 17:38 2009-07-15 Show GitHub Exploit DB Packet Storm
240194 7.2 危険 Linux - Linux kernel の ext4 ファイルシステムにおける任意のファイルを上書きをされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4131 2012-09-25 17:38 2009-12-12 Show GitHub Exploit DB Packet Storm
240195 5.8 警告 Mozilla Foundation - Mozilla Firefox の nsGlobalWindow.cpp におけるスクリプトの元のドメイン名を偽造される脆弱性 CWE-Other
その他
CVE-2009-4130 2012-09-25 17:38 2009-12-14 Show GitHub Exploit DB Packet Storm
240196 5.8 警告 Mozilla Foundation - Mozilla Firefox における偽造されたドメインアソシエーションで JavaScript メッセージを生成される脆弱性 CWE-362
競合状態
CVE-2009-4129 2012-09-25 17:38 2009-12-14 Show GitHub Exploit DB Packet Storm
240197 6.8 警告 OpenSolution - Quick.CMS および Quick.CMS.Lite におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4121 2012-09-25 17:38 2009-11-30 Show GitHub Exploit DB Packet Storm
240198 6.8 警告 OpenSolution - Quick.Cart におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4120 2012-09-25 17:38 2009-11-30 Show GitHub Exploit DB Packet Storm
240199 4.9 警告 カスペルスキー - Kaspersky Anti-Virus の kl1.sys におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-4114 2012-09-25 17:38 2009-11-30 Show GitHub Exploit DB Packet Storm
240200 6.8 警告 PEAR - PEAR の Mail パッケージにおける任意のファイルを読み書きされる脆弱性 CWE-94
コード・インジェクション
CVE-2009-4111 2012-09-25 17:38 2009-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
771 7.5 HIGH
Network
envoyproxy envoy Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete a… Update CWE-444
HTTP Request Smuggling
CVE-2026-48743 2026-06-30 03:27 2026-06-27 Show GitHub Exploit DB Packet Storm
772 5.9 MEDIUM
Network
envoyproxy envoy Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentat… New CWE-416
 Use After Free
CVE-2026-47205 2026-06-30 03:21 2026-06-27 Show GitHub Exploit DB Packet Storm
773 5.9 MEDIUM
Network
- - Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem… New CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-57959 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
774 6.1 MEDIUM
Network
- - Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malici… New CWE-79
Cross-site Scripting
CVE-2026-57958 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
775 4.7 MEDIUM
Network
- - Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by e… New CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-57957 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
776 6.4 MEDIUM
Network
- - SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule sto… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-57956 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
777 8.5 HIGH
Network
- - SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path paramet… New CWE-89
SQL Injection
CVE-2026-57955 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
778 8.1 HIGH
Network
- - ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorize… New CWE-863
 Incorrect Authorization
CVE-2026-57950 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
779 6.5 MEDIUM
Network
- - ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated u… New CWE-862
 Missing Authorization
CVE-2026-57949 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm
780 8.5 HIGH
Network
- - Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protecti… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-57947 2026-06-30 03:16 2026-06-30 Show GitHub Exploit DB Packet Storm