Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240411 7.5 危険 p3mbo - Content Injector の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6394 2012-09-25 16:59 2007-12-17 Show GitHub Exploit DB Packet Storm
240412 9.3 危険 マイクロソフト
Intuit
vantage linquistics
- Vantage Linguistics AnswerWorks におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6387 2012-09-25 16:59 2007-12-11 Show GitHub Exploit DB Packet Storm
240413 2.1 注意 Kerio Technologies - Kerio WinRoute Firewall のプロキシサーバにおける脆弱性 CWE-287
不適切な認証
CVE-2007-6385 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240414 7.1 危険 ノキア - RM-159 ファームウェアを伴う Nokia N95 携帯電話におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6371 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240415 4.3 警告 jlmforo system - JLMForo System の modificarPerfil.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6364 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240416 2.1 注意 IBM - IBM Tivoli Netcool Security Manager におけるログインアクセス権を取得される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6363 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240417 7.5 危険 Joomla! - Mambo および Joomla! 用の RSGallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6362 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240418 5.8 警告 マイクロソフト - Microsoft Office Access におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6357 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
240419 7.8 危険 Perforce Software - Perforce P4Web の P4Webs.exe におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-6349 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
240420 6.8 警告 mcms - Mcms Easy Web Make の modules/cms/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6344 2012-09-25 16:59 2007-12-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2251 9.6 CRITICAL
Network
- - Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CWE-787
 Out-of-bounds Write
CVE-2026-11037 2026-06-6 02:16 2026-06-5 Show GitHub Exploit DB Packet Storm
2252 6.5 MEDIUM
Network
- - CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial … CWE-20
 Improper Input Validation 
CVE-2025-5090 2026-06-6 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
2253 6.5 MEDIUM
Network
- - In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain … CWE-20
 Improper Input Validation 
CVE-2025-5089 2026-06-6 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
2254 8.3 HIGH
Network
- - An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on… CWE-269
 Improper Privilege Management
CVE-2025-5088 2026-06-6 02:16 2026-06-6 Show GitHub Exploit DB Packet Storm
2255 5.5 MEDIUM
Local
linaro op-tee OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior t… CWE-843
Type Confusion
CVE-2026-45702 2026-06-6 01:56 2026-06-4 Show GitHub Exploit DB Packet Storm
2256 7.5 HIGH
Network
microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. CWE-285
Improper Authorization
CVE-2026-48579 2026-06-6 01:51 2026-06-5 Show GitHub Exploit DB Packet Storm
2257 8.8 HIGH
Network
dlink dwr-m920_firmware A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-10878 2026-06-6 01:48 2026-06-5 Show GitHub Exploit DB Packet Storm
2258 3.1 LOW
Network
google chrome Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy… CWE-20
 Improper Input Validation 
CVE-2026-11244 2026-06-6 01:43 2026-06-5 Show GitHub Exploit DB Packet Storm
2259 5.4 MEDIUM
Network
google chrome Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) CWE-346
 Origin Validation Error
CVE-2026-11243 2026-06-6 01:43 2026-06-5 Show GitHub Exploit DB Packet Storm
2260 9.8 CRITICAL
Network
microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. CWE-290
 Authentication Bypass by Spoofing
CVE-2026-48567 2026-06-6 01:30 2026-06-5 Show GitHub Exploit DB Packet Storm