Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240771 4.3 警告 Invision Power Services, Inc - IP.Board の ips_kernel/class_ajax.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4912 2012-09-25 16:59 2007-09-12 Show GitHub Exploit DB Packet Storm
240772 10 危険 netinvoicing - netInvoicing における脆弱性 CWE-noinfo
情報不足
CVE-2007-4910 2012-09-25 16:59 2007-09-17 Show GitHub Exploit DB Packet Storm
240773 6.8 警告 nuclearbb - NuclearBB の tasks/send_queued_emails.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4906 2012-09-25 16:59 2007-09-17 Show GitHub Exploit DB Packet Storm
240774 6.8 警告 マイクロソフト - Microsoft Visual Studio 6.0 の PDWizard.ocx における任意のプログラムを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2007-4891 2012-09-25 16:59 2007-09-13 Show GitHub Exploit DB Packet Storm
240775 5.8 警告 マイクロソフト - Microsoft Visual Studio 6.0 の VBTOVSI.DLL におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4890 2012-09-25 16:59 2007-09-13 Show GitHub Exploit DB Packet Storm
240776 6.8 警告 The PHP Group - PHP の MySQL エクステンションにおける open_basedir 制限を回避される脆弱性 CWE-DesignError
CVE-2007-4889 2012-09-25 16:59 2007-09-13 Show GitHub Exploit DB Packet Storm
240777 4.3 警告 media player classic - MPC におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-4884 2012-09-25 16:59 2007-09-13 Show GitHub Exploit DB Packet Storm
240778 4.3 警告 MediaWiki - MediaWiki の BotQuery エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4883 2012-09-25 16:59 2007-09-10 Show GitHub Exploit DB Packet Storm
240779 10 危険 IBM - IBM TSM クライアントの CAD におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4880 2012-09-25 16:59 2007-09-20 Show GitHub Exploit DB Packet Storm
240780 4.4 警告 one laptop per child - JFFS2 における制限されたファイルへアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-4849 2012-09-25 16:59 2007-09-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
971 4.3 MEDIUM
Network
- - In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR ap… CWE-117
 Improper Output Neutralization for Logs
CVE-2026-20260 2026-06-11 03:36 2026-06-11 Show GitHub Exploit DB Packet Storm
972 5.7 MEDIUM
Network
- - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that… CWE-20
 Improper Input Validation 
CVE-2026-20257 2026-06-11 03:36 2026-06-11 Show GitHub Exploit DB Packet Storm
973 9.6 CRITICAL
Adjacent
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati… CWE-20
 Improper Input Validation 
CVE-2026-47928 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
974 8.4 HIGH
Adjacent
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privi… CWE-863
 Incorrect Authorization
CVE-2026-47929 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
975 8.1 HIGH
Network
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi… CWE-20
 Improper Input Validation 
CVE-2026-47930 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
976 8.4 HIGH
Adjacent
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati… CWE-20
 Improper Input Validation 
CVE-2026-47931 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
977 8.8 HIGH
Adjacent
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature… CWE-22
Path Traversal
CVE-2026-47932 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
978 4.8 MEDIUM
Adjacent
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vu… CWE-79
Cross-site Scripting
CVE-2026-47933 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
979 10.0 CRITICAL
Network
- - Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this i… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-47938 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
980 7.4 HIGH
Network
- - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attack… CWE-611
XXE
CVE-2026-47960 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm