Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3561 6.1 警告
Network
Joomla! Joomla! Joomla!におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-30894 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3562 6.1 警告
Network
Joomla! Joomla! Joomla!におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-30895 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3563 9.8 緊急
Network
マイクロソフト Microsoft Entra ID Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2026-33843 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
3564 4.3 警告
Network
Joomla! Joomla! Joomla!におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-35220 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3565 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-35221 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3566 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-35222 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3567 8.8 重要
Network
FreeRDP FreeRDP FreeRDPにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40033 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3568 9.8 緊急
Network
Joomla! Joomla! Joomla!におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40383 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3569 7.2 重要
Network
IBM Engineering Lifecycle Management IBMのEngineering Lifecycle Managementにおける危険なメソッドや機能の公開に関する脆弱性 CWE-749
危険なメソッドや機能の公開
CVE-2026-4051 2026-05-29 11:17 2026-05-26 Show GitHub Exploit DB Packet Storm
3570 6.5 警告
Network
struktur AG libheif struktur AGのlibheifにおける複数の脆弱性 CWE-125
CWE-476
CVE-2026-41069 2026-05-29 11:17 2026-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
344391 - miraks miraksgalerie Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php whe… NVD-CWE-Other
CVE-2006-2922 2018-10-19 01:43 2006-06-9 Show GitHub Exploit DB Packet Storm
344392 - loudhush loudhush The iax_net_read function in the iaxclient open source library, as used in multiple products including (a) LoudHush 1.3.6, (b) IDE FISK 1.35 and earlier, (c) Kiax 0.8.5 and earlier, (d) DIAX, (e) Zia… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2006-2923 2018-10-19 01:43 2006-06-9 Show GitHub Exploit DB Packet Storm
344393 - cms-bandits cms-bandits Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root pa… NVD-CWE-Other
CVE-2006-2928 2018-10-19 01:43 2006-06-9 Show GitHub Exploit DB Packet Storm
344394 - hotwebscripts cms_mundo CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files. NVD-CWE-Other
CVE-2006-2931 2018-10-19 01:43 2006-06-22 Show GitHub Exploit DB Packet Storm
344395 - mozilla firefox
seamonkey
Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to execute arbitrary code by using the nsISelectionPrivate interface of the Selection ob… NVD-CWE-Other
CVE-2006-2777 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm
344396 - mozilla firefox
seamonkey
This vulnerability is addressed in the following product releases: Mozilla, Firefox, 1.5.0.4 Mozilla, SeaMonkey, 1.0.2 NVD-CWE-Other
CVE-2006-2777 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm
344397 - mozilla firefox
thunderbird
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which cause… NVD-CWE-Other
CVE-2006-2778 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm
344398 - mozilla firefox
thunderbird
Fixed in: Firefox 1.5.0.4 Thunderbird 1.5.0.4 SeaMonkey 1.0.2 NVD-CWE-Other
CVE-2006-2778 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm
344399 - mozilla firefox
thunderbird
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMN… CWE-94
Code Injection
CVE-2006-2779 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm
344400 - mozilla firefox
thunderbird
Fixed in: Firefox 1.5.0.4 Thunderbird 1.5.0.4 SeaMonkey 1.0.2 CWE-94
Code Injection
CVE-2006-2779 2018-10-19 01:42 2006-06-3 Show GitHub Exploit DB Packet Storm