Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3391 9.8 緊急
Network
Mauricio Poppe (mauriciopoppe) math-codegen Mauricio Poppe (mauriciopoppe)のmath-codegenにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41507 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
3392 9.8 緊急
Network
CROSS-CRYPT.COM CROSS CROSS-CRYPT.COMのCROSSにおける複数の脆弱性 CWE-121
CWE-122
CVE-2026-41509 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
3393 7.5 重要
Network
DCIT CryptX DCITのCryptXにおける複数の脆弱性 CWE-335
CWE-338
CVE-2026-41564 2026-05-14 10:12 2026-04-23 Show GitHub Exploit DB Packet Storm
3394 6.1 警告
Network
th30d4y w4nn4d13/ip th30d4yのw4nn4d13/ipにおける複数の脆弱性 CWE-79
CWE-79
CWE-80
CVE-2026-41575 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
3395 7.8 重要
Local
dail8859 Notepad Next dail8859のNotepad Nextにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-42214 2026-05-14 10:12 2026-05-7 Show GitHub Exploit DB Packet Storm
3396 7.1 重要
Network
Legeling PromptHUB LegelingのPromptHUBにおける複数の脆弱性 CWE-20
CWE-693
CWE-918
CVE-2026-42261 2026-05-14 10:12 2026-05-8 Show GitHub Exploit DB Packet Storm
3397 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-862
CVE-2026-42809 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
3398 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-116
CWE-20
CVE-2026-42810 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
3399 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-917
CVE-2026-42811 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
3400 9.9 緊急
Network
Apache Software Foundation Polaris Apache Software FoundationのPolarisにおける複数の脆弱性 CWE-20
CWE-284
CWE-732
CWE-863
CVE-2026-42812 2026-05-14 10:12 2026-05-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306281 - cisco sa500_software
sa520
sa520w
sa540
The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2547 2024-11-21 10:28 2011-07-29 Show GitHub Exploit DB Packet Storm
306282 - cisco sa500_software
sa520
sa520w
sa540
SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via … CWE-89
SQL Injection
CVE-2011-2546 2024-11-21 10:28 2011-07-29 Show GitHub Exploit DB Packet Storm
306283 - linux
redhat
linux_kernel
enterprise_linux_server
enterprise_linux_workstation
enterprise_linux_desktop
enterprise_linux_eus
enterprise_linux_aus
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memor… CWE-200
Information Exposure
CVE-2011-2492 2024-11-21 10:28 2011-07-29 Show GitHub Exploit DB Packet Storm
306284 - google picasa Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file. CWE-94
Code Injection
CVE-2011-2747 2024-11-21 10:28 2011-07-29 Show GitHub Exploit DB Packet Storm
306285 - mod_authnz_external_project
debian
mod_authnz_external
debian_linux
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the use… CWE-89
SQL Injection
CVE-2011-2688 2024-11-21 10:28 2011-07-29 Show GitHub Exploit DB Packet Storm
306286 - joomla joomla\! Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable throug… CWE-79
Cross-site Scripting
CVE-2011-2710 2024-11-21 10:28 2011-07-28 Show GitHub Exploit DB Packet Storm
306287 - joomla joomla\! Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2011-2488 2024-11-21 10:28 2011-07-28 Show GitHub Exploit DB Packet Storm
306288 - chyrp chyrp upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2745 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306289 - mega-nerd libsndfile Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file th… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2696 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm
306290 - drupal drupal Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table. CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2687 2024-11-21 10:28 2011-07-27 Show GitHub Exploit DB Packet Storm