Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1341 5.9 警告
Local
libexpat project libexpat libexpat projectのlibexpatにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-50219 2026-06-8 11:45 2026-06-4 Show GitHub Exploit DB Packet Storm
1342 5.3 警告
Network
morgan project morgan morgan projectのmorganにおける不適切なログ出力の無効化に関する脆弱性 CWE-117
不適切なログ出力の無効化
CVE-2026-5078 2026-06-8 11:45 2026-06-3 Show GitHub Exploit DB Packet Storm
1343 9.6 緊急
Network
huggingface transformers huggingfaceのtransformersにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-5241 2026-06-8 11:45 2026-06-3 Show GitHub Exploit DB Packet Storm
1344 8.1 重要
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-7195 2026-06-8 11:45 2026-06-2 Show GitHub Exploit DB Packet Storm
1345 9.8 緊急
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-7198 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1346 8.8 重要
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-7201 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1347 5.4 警告
Network
appsmith appsmith appsmithにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-7299 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1348 7.5 重要
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-7312 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1349 4.9 警告
Network
Progress Software Corporation Sitefinity Progress Software CorporationのSitefinityにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-7313 2026-06-8 11:44 2026-06-2 Show GitHub Exploit DB Packet Storm
1350 8.8 重要
Network
SmarterTools Inc. SmarterMail SmarterTools Inc.のSmarterMailにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-7807 2026-06-8 11:44 2026-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
310571 8.8 HIGH
Network
pixelpost pixelpost Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password. CWE-352
 Origin Validation Error
CVE-2010-3305 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310572 6.5 MEDIUM
Network
rubyonrails
debian
rails
debian_linux
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. CWE-311
Missing Encryption of Sensitive Data
CVE-2010-3299 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310573 5.5 MEDIUM
Local
mailscanner mailscanner The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to… CWE-311
Missing Encryption of Sensitive Data
CVE-2010-3292 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310574 4.7 MEDIUM
Local
mailscanner mailscanner mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-… CWE-59
Link Following
CVE-2010-3095 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310575 6.5 MEDIUM
Network
cor-entertainment
debian
fedoraproject
alien-arena
debian_linux
fedora
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command. CWE-20
 Improper Input Validation 
CVE-2010-3439 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310576 9.8 CRITICAL
Network
libpoe-component-irc-perl_project
debian
fedoraproject
libpoe-component-irc-perl
debian_linux
fedora
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'pri… CWE-134
Use of Externally-Controlled Format String
CVE-2010-3438 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310577 4.8 MEDIUM
Local
gargoyle_project
debian
gargoyle
debian_linux
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a dire… CWE-20
 Improper Input Validation 
CVE-2010-3359 2024-11-21 10:18 2019-11-13 Show GitHub Exploit DB Packet Storm
310578 9.8 CRITICAL
Network
qtparted_project qtparted qtparted has insecure library loading which may allow arbitrary code execution CWE-20
 Improper Input Validation 
CVE-2010-3375 2024-11-21 10:18 2019-10-30 Show GitHub Exploit DB Packet Storm
310579 5.5 MEDIUM
Local
grsecurity
debian
paxtest
debian_linux
paxtest handles temporary files insecurely CWE-20
 Improper Input Validation 
CVE-2010-3373 2024-11-21 10:18 2019-10-30 Show GitHub Exploit DB Packet Storm
310580 5.5 MEDIUM
Local
mailscanner mailscanner mailscanner can allow local users to prevent virus signatures from being updated CWE-20
 Improper Input Validation 
CVE-2010-3293 2024-11-21 10:18 2019-10-29 Show GitHub Exploit DB Packet Storm