Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 6:13 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3431 9.8 緊急
Network
The PHP Group PHP The PHP GroupのPHPにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-14179 2026-05-14 10:23 2026-05-10 Show GitHub Exploit DB Packet Storm
3432 7.5 重要
Network
IBM watsonx.data IBMのwatsonx.dataにおける意図するエンドポイントとの通信チャネルの制限に関する脆弱性 CWE-923
意図するエンドポイントとの通信チャネルの不適切な制限
CVE-2025-36180 2026-05-14 10:23 2026-04-30 Show GitHub Exploit DB Packet Storm
3433 5.5 警告
Local
IBM watsonx.data IBMのwatsonx.dataにおける認証情報の平文保存に関する脆弱性 CWE-256
平文でパスワードを保存
CVE-2025-36335 2026-05-14 10:23 2026-04-30 Show GitHub Exploit DB Packet Storm
3434 7.5 重要
Network
アップル iOS
iPadOS
アップルのiPadOS等の複数製品におけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2025-46311 2026-05-14 10:23 2026-05-12 Show GitHub Exploit DB Packet Storm
3435 4.7 警告
Network
ISPConfig ISPConfig ISPConfigにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-52206 2026-05-14 10:23 2026-05-5 Show GitHub Exploit DB Packet Storm
3436 7.3 重要
Network
AstrBot AstrBot AstrBotにおけるハードコードされた暗号鍵の使用に関する脆弱性 CWE-321
ハードコードされた暗号鍵の使用
CVE-2025-55449 2026-05-14 10:23 2026-05-8 Show GitHub Exploit DB Packet Storm
3437 7.2 重要
Network
Check MK Check MK Check MKにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2025-64998 2026-05-14 10:22 2026-03-24 Show GitHub Exploit DB Packet Storm
3438 6.5 警告
Network
Apache Software Foundation CloudStack Apache Software FoundationのCloudStackにおける認可されていない行為者への個人情報の漏えいに関する脆弱性 CWE-359
認可されていないアクターへの個人情報の漏えい
CVE-2025-66171 2026-05-14 10:22 2026-05-8 Show GitHub Exploit DB Packet Storm
3439 8.1 重要
Network
Apache Software Foundation CloudStack Apache Software FoundationのCloudStackにおける認可されていない行為者への個人情報の漏えいに関する脆弱性 CWE-359
認可されていないアクターへの個人情報の漏えい
CVE-2025-66172 2026-05-14 10:22 2026-05-8 Show GitHub Exploit DB Packet Storm
3440 7.2 重要
Network
Dolibarr ERP & CRM dolibarr erp/crm Dolibarr ERP & CRMのdolibarr erp/crmにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2025-67486 2026-05-14 10:22 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
306261 - google
apple
debian
chrome
iphone_os
itunes
safari
debian_linux
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown… CWE-20
 Improper Input Validation 
CVE-2011-2359 2024-11-21 10:28 2011-08-3 Show GitHub Exploit DB Packet Storm
306262 - google chrome Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via … CWE-20
 Improper Input Validation 
CVE-2011-2358 2024-11-21 10:28 2011-08-3 Show GitHub Exploit DB Packet Storm
306263 - phpmyadmin phpmyadmin libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attac… CWE-20
 Improper Input Validation 
CVE-2011-2719 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306264 - phpmyadmin phpmyadmin Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files v… CWE-22
Path Traversal
CVE-2011-2718 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306265 - osgeo
umn
mapserver Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2704 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306266 - osgeo
umn
mapserver Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filte… CWE-89
SQL Injection
CVE-2011-2703 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306267 - phpmyadmin phpmyadmin Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via direct… CWE-22
Path Traversal
CVE-2011-2643 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306268 - phpmyadmin phpmyadmin Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users… CWE-79
Cross-site Scripting
CVE-2011-2642 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306269 - hp network_automation SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2011-2403 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm
306270 - hp network_automation Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2011-2402 2024-11-21 10:28 2011-08-2 Show GitHub Exploit DB Packet Storm