Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240391 6.5 警告 hosting controller - Hosting Controller の inc_newuser.asp におけるディレクトリ名 db のパーミッションを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6495 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240392 10 危険 hosting controller - Hosting Controller におけるログインアクセスを取得される脆弱性 CWE-20
不適切な入力確認
CVE-2007-6494 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240393 10 危険 imesh.com - iMesh の IMWeb.dll における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-6493 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240394 7.1 危険 imesh.com - iMesh の IMWeb.dll および IMWebControl.dll におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6492 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240395 10 危険 kvaliitti - Kvaliitti WebDoc CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6491 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240396 9.3 危険 hammer of thyrion - Hammer of Thyrion の HuffDecode 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6468 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
240397 7.5 危険 mkportal - MKPortal の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6467 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
240398 4.3 警告 php real estate script - PHP Real Estate Classifieds の管理パネルにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6463 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
240399 7.5 危険 php real estate classifieds - PHP Real Estate Classifieds の fullnews.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6462 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
240400 7.5 危険 my123tkshop - 123tkShop の shop/mainfile.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6458 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
551 8.8 HIGH
Network
nsa ghidra Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by pres… Update CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-52754 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
552 5.5 MEDIUM
Local
nsa ghidra Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names… Update CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-52753 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
553 5.7 MEDIUM
Adjacent
microsoft windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2022
windows_server_2025
Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network. Update CWE-131
Incorrect Calculation of Buffer Size
CVE-2026-42915 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
554 7.8 HIGH
Local
nsa ghidra Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with travers… Update CWE-22
Path Traversal
CVE-2026-52752 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
555 8.8 HIGH
Network
nsa ghidra Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a maliciou… Update CWE-502
 Deserialization of Untrusted Data
CVE-2026-52751 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
556 5.3 MEDIUM
Network
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Windows Kerberos Denial of Service Vulnerability Update CWE-125
Out-of-bounds Read
CVE-2026-42914 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
557 7.8 HIGH
Local
nsa ghidra Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands und… Update CWE-88
Argument Injection
CVE-2026-52750 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
558 8.8 HIGH
Network
nsa ghidra Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE … Update CWE-89
SQL Injection
CVE-2026-49498 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm
559 3.3 LOW
Local
nsa ghidra Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attacke… Update CWE-22
Path Traversal
CVE-2026-49497 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm
560 6.1 MEDIUM
Local
nsa ghidra Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vecto… Update CWE-416
 Use After Free
CVE-2026-49496 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm