Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223251 5 警告 株式会社ロックオン - EC-CUBE における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2013-5994 2014-01-30 18:32 2013-11-20 Show GitHub Exploit DB Packet Storm
223252 6.4 警告 株式会社ロックオン - EC-CUBE におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2314 2014-01-30 18:31 2013-05-23 Show GitHub Exploit DB Packet Storm
223253 6 警告 Chamilo Association - Chamilo LMS の main/auth/profile.php の check_user_password 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-6787 2014-01-30 15:53 2013-11-6 Show GitHub Exploit DB Packet Storm
223254 5 警告 Easytime Studio - iOS 用 Easytime Studio Easy File Manager におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-3921 2014-01-30 15:52 2013-11-21 Show GitHub Exploit DB Packet Storm
223255 7.5 危険 Doug Poulin - Command School Student Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-1636 2014-01-30 14:46 2014-01-7 Show GitHub Exploit DB Packet Storm
223256 5 警告 Doug Poulin - Command School Student Management System におけるデータベースのバックアップをダウンロードされる脆弱性 CWE-200
情報漏えい
CVE-2014-1637 2014-01-30 14:45 2014-01-7 Show GitHub Exploit DB Packet Storm
223257 9.3 危険 ジャストシステム - 三四郎シリーズにおいて任意のコードが実行される脆弱性 CWE-noinfo
情報不足
CVE-2014-0810 2014-01-30 14:24 2014-01-28 Show GitHub Exploit DB Packet Storm
223258 6.5 警告 サイボウズ - サイボウズ ガルーンにおける複数の SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-6930
CVE-2013-6931
2014-01-30 14:20 2014-01-28 Show GitHub Exploit DB Packet Storm
223259 7.1 危険 ジュニパーネットワークス - Juniper Junos におけるサービス運用妨害 (DoS) の脆弱性 CWE-362
競合状態
CVE-2014-0616 2014-01-30 14:18 2014-01-8 Show GitHub Exploit DB Packet Storm
223260 7.2 危険 ジュニパーネットワークス - Juniper Junos における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0615 2014-01-30 14:16 2014-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
761 6.5 MEDIUM
Network
- - Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. New CWE-476
 NULL Pointer Dereference
CVE-2026-42903 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
762 7.8 HIGH
Local
- - Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. New CWE-285
Improper Authorization
CVE-2026-42902 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
763 7.8 HIGH
Local
- - Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. New CWE-125
Out-of-bounds Read
CVE-2026-42837 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
764 7.0 HIGH
Local
- - Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. New CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2026-42836 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
765 8.1 HIGH
Network
- - Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. New CWE-74
Injection
CVE-2026-42835 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
766 7.8 HIGH
Local
- - Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. New CWE-284
Improper Access Control
CVE-2026-42829 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
767 7.8 HIGH
Local
- - Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. New CWE-126
 Buffer Over-read
CVE-2026-42828 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
768 - - - Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML … New CWE-79
Cross-site Scripting
CVE-2026-42599 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
769 - - - Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This … New CWE-79
Cross-site Scripting
CVE-2026-42573 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm
770 7.5 HIGH
Network
- - Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to qu… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-42570 2026-06-10 02:17 2026-06-10 Show GitHub Exploit DB Packet Storm