Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222091 7.5 危険 Arial Software - Arial Software Campaign Enterprise の Campaign11.exe における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-3820 2014-08-15 18:18 2012-10-18 Show GitHub Exploit DB Packet Storm
222092 4.3 警告 MyBB Group - MyBB におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5248 2014-08-15 16:59 2014-08-4 Show GitHub Exploit DB Packet Storm
222093 4.3 警告 Mozilla Foundation - Bugzilla の jsonrpc.cgi の WebService/Server/JSONRPC.pm の JSONP エンドポイント内の response 関数におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-1546 2014-08-15 15:33 2014-07-24 Show GitHub Exploit DB Packet Storm
222094 4.3 警告 Piwigo - Piwigo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1980 2014-08-15 13:35 2014-08-8 Show GitHub Exploit DB Packet Storm
222095 3.5 注意 Compfight - WordPress 用 Compfight プラグインの compfight-search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5202 2014-08-15 12:36 2014-07-3 Show GitHub Exploit DB Packet Storm
222096 6.5 警告 シスコシステムズ - Cisco Unified Communications Manager および Cisco Unified Presence Server の管理 Web インターフェースにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3339 2014-08-15 12:04 2014-08-12 Show GitHub Exploit DB Packet Storm
222097 8.5 危険 シスコシステムズ - Cisco Unified Communications Manager の CTIManager モジュールにおける権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2014-3338 2014-08-15 12:04 2014-08-11 Show GitHub Exploit DB Packet Storm
222098 6.8 警告 シスコシステムズ - Cisco Unified Communications Manager の SIP の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3337 2014-08-15 12:03 2014-08-11 Show GitHub Exploit DB Packet Storm
222099 4.4 警告 Puppet - Puppet Enterprise および Mcollective で使用される MCollective aes_security プラグインにおける許可されていない Mcollective 接続を確立される脆弱性 CWE-362
競合状態
CVE-2014-3251 2014-08-15 10:54 2014-07-15 Show GitHub Exploit DB Packet Storm
222100 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-3167 2014-08-15 10:47 2014-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
901 7.5 HIGH
Network
- - A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string. CWE-400
 Uncontrolled Resource Consumption
CVE-2026-38640 2026-06-26 23:17 2026-06-26 Show GitHub Exploit DB Packet Storm
902 4.2 MEDIUM
Network
- - The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Googl… CWE-862
 Missing Authorization
CVE-2026-2299 2026-06-26 23:17 2026-06-26 Show GitHub Exploit DB Packet Storm
903 8.1 HIGH
Network
- - vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability CWE-129
 Improper Validation of Array Index
CVE-2026-22879 2026-06-26 23:17 2026-06-26 Show GitHub Exploit DB Packet Storm
904 - - - ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.35 in Java applications, allows an attacker to execute arbitrary code circumvent… CWE-20
 Improper Input Validation 
CVE-2026-13006 2026-06-26 23:16 2026-06-24 Show GitHub Exploit DB Packet Storm
905 8.2 HIGH
Network
- - Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-12473 2026-06-26 23:16 2026-06-26 Show GitHub Exploit DB Packet Storm
906 7.8 HIGH
Local
- - A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafte… CWE-416
 Use After Free
CVE-2025-60464 2026-06-26 23:16 2026-06-26 Show GitHub Exploit DB Packet Storm
907 7.8 HIGH
Local
mmaitre314 picklescan picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that execut… CWE-502
 Deserialization of Untrusted Data
CVE-2025-71357 2026-06-26 23:14 2026-06-21 Show GitHub Exploit DB Packet Storm
908 7.8 HIGH
Local
mmaitre314 picklescan picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection… CWE-502
 Deserialization of Untrusted Data
CVE-2025-71378 2026-06-26 23:12 2026-06-21 Show GitHub Exploit DB Packet Storm
909 9.8 CRITICAL
Network
kidocode crawl4ai Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentic… CWE-798
 Use of Hard-coded Credentials
CVE-2026-56265 2026-06-26 22:52 2026-06-21 Show GitHub Exploit DB Packet Storm
910 9.1 CRITICAL
Network
imagemagick imagemagick ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on … CWE-125
Out-of-bounds Read
CVE-2026-56367 2026-06-26 22:50 2026-06-21 Show GitHub Exploit DB Packet Storm