Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223841 5 警告 デル - Dell Quest One Password Manager におけるキャプチャの保護を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6246 2013-10-28 14:25 2013-10-21 Show GitHub Exploit DB Packet Storm
223842 10 危険 デル - Dell iDRAC の BMC の実装における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-4783 2013-10-28 14:24 2013-07-8 Show GitHub Exploit DB Packet Storm
223843 3.2 注意 レッドハット - Red Hat JBoss Operations Network の JPADriftServerBean における任意のドリフトファイルをサーバにロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2013-4373 2013-10-28 14:10 2013-10-21 Show GitHub Exploit DB Packet Storm
223844 2.1 注意 レッドハット - Red Hat JBoss Operations Network のサーバにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-4293 2013-10-28 14:05 2013-10-21 Show GitHub Exploit DB Packet Storm
223845 4.3 警告 Mozilla Foundation - Bugzilla の report.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1743 2013-10-28 13:39 2013-10-13 Show GitHub Exploit DB Packet Storm
223846 4.3 警告 Mozilla Foundation - Bugzilla の editflagtypes.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1742 2013-10-28 13:37 2013-10-9 Show GitHub Exploit DB Packet Storm
223847 6.8 警告 Mozilla Foundation - Bugzilla の attachment.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-1734 2013-10-28 13:35 2013-09-8 Show GitHub Exploit DB Packet Storm
223848 6.8 警告 Mozilla Foundation - Bugzilla の process_bug.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-1733 2013-10-28 13:33 2013-09-1 Show GitHub Exploit DB Packet Storm
223849 5.8 警告 Apache Software Foundation - Apache Sling の Auth Core バンドルの AbstractAuthenticationFormServlet におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-4390 2013-10-28 11:57 2013-10-3 Show GitHub Exploit DB Packet Storm
223850 5 警告 Apache Software Foundation - PHP 用 Apache Shindig の gadget レンダラにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-4295 2013-10-28 11:53 2013-10-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1051 6.5 MEDIUM
Network
vmware spring_ai Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int… Update CWE-22
Path Traversal
CVE-2026-41863 2026-06-1 23:22 2026-05-25 Show GitHub Exploit DB Packet Storm
1052 7.7 HIGH
Network
elastic kibana Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connec… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-42398 2026-06-1 23:17 2026-05-29 Show GitHub Exploit DB Packet Storm
1053 6.5 MEDIUM
Network
elastic kibana Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentiall… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-42399 2026-06-1 23:14 2026-05-29 Show GitHub Exploit DB Packet Storm
1054 6.5 MEDIUM
Network
elastic kibana Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-42400 2026-06-1 23:13 2026-05-29 Show GitHub Exploit DB Packet Storm
1055 7.7 HIGH
Network
elastic kibana Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server t… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-49093 2026-06-1 23:13 2026-05-29 Show GitHub Exploit DB Packet Storm
1056 7.8 HIGH
Local
jetbrains intellij_idea In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin Update CWE-1336
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-49382 2026-06-1 22:59 2026-05-30 Show GitHub Exploit DB Packet Storm
1057 7.8 HIGH
Local
jetbrains intellij_idea In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion Update CWE-78
OS Command 
CVE-2026-49366 2026-06-1 22:59 2026-05-30 Show GitHub Exploit DB Packet Storm
1058 3.3 LOW
Local
jetbrains intellij_idea In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible Update CWE-611
XXE
CVE-2026-49383 2026-06-1 22:58 2026-05-30 Show GitHub Exploit DB Packet Storm
1059 8.8 HIGH
Network
jetbrains intellij_idea In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account Update CWE-862
 Missing Authorization
CVE-2026-49367 2026-06-1 22:56 2026-05-30 Show GitHub Exploit DB Packet Storm
1060 6.5 MEDIUM
Network
elastic kibana Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containin… Update CWE-400
 Uncontrolled Resource Consumption
CVE-2026-49094 2026-06-1 22:31 2026-05-29 Show GitHub Exploit DB Packet Storm