Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 6:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224441 9.3 危険 Mozilla Foundation - 複数の Mozilla 製品の Animation Manager における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2013-1722 2013-10-15 17:37 2013-09-17 Show GitHub Exploit DB Packet Storm
224442 3.7 注意 アップル - iPad デバイス上の Apple iOS の XNU kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-3955 2013-10-15 17:15 2013-04-26 Show GitHub Exploit DB Packet Storm
224443 9.3 危険 Mozilla Foundation - Mozilla Firefox および SeaMonkey で使用される Almost Native Graphics Layer Engine における整数オーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1721 2013-10-15 17:02 2013-09-17 Show GitHub Exploit DB Packet Storm
224444 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-1720 2013-10-15 16:59 2013-09-17 Show GitHub Exploit DB Packet Storm
224445 10 危険 Mozilla Foundation - 複数の Mozilla 製品のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-1719 2013-10-15 16:55 2013-09-17 Show GitHub Exploit DB Packet Storm
224446 10 危険 Mozilla Foundation - 複数の Mozilla 製品のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-1718 2013-10-15 16:53 2013-09-17 Show GitHub Exploit DB Packet Storm
224447 10 危険 Mozilla Foundation - Mozilla Firefox および SeaMonkey の cryptojs_interpret_key_gen_type 関数におけるヒープベースのバッファアンダーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1705 2013-10-15 16:50 2013-08-6 Show GitHub Exploit DB Packet Storm
224448 7.5 危険 Fast Permissions Administration - Drupal 用 Fast Permissions Administration モジュールにおける不特定のアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2247 2013-10-15 16:39 2013-06-26 Show GitHub Exploit DB Packet Storm
224449 5.8 警告 Node access user reference - Drupal 用 Node access user reference モジュールにおけるコンテンツを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2123 2013-10-15 16:37 2013-05-29 Show GitHub Exploit DB Packet Storm
224450 7.8 危険 アップル - Apple iOS のカーネルにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-5140 2013-10-15 15:10 2013-09-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1911 6.3 MEDIUM
Network
- - A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can … CWE-266
CWE-284
 Incorrect Privilege Assignment
Improper Access Control
CVE-2026-9581 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
1912 7.5 HIGH
Network
archive\ \ Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), … CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-9538 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1913 7.5 HIGH
Network
- - The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. CWE-524
 Use of Cache Containing Sensitive Information
CVE-2026-48901 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
1914 7.8 HIGH
Local
- - A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca… CWE-787
 Out-of-bounds Write
CVE-2026-48864 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
1915 7.7 HIGH
Network
- - Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45715 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
1916 10.0 CRITICAL
Network
- - Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by de… CWE-15
CWE-78
CWE-306
 External Control of System or Configuration Setting
OS Command 
Missing Authentication for Critical Function
CVE-2026-45087 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
1917 5.0 MEDIUM
Network
- - Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate … CWE-78
CWE-1336
OS Command 
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-44723 2026-05-28 23:16 2026-05-27 Show GitHub Exploit DB Packet Storm
1918 7.9 HIGH
Local
- - pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption… CWE-59
CWE-287
Link Following
Improper Authentication
CVE-2026-44711 2026-05-28 23:16 2026-05-28 Show GitHub Exploit DB Packet Storm
1919 7.5 HIGH
Network
archive\ \ Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without va… CWE-59
CWE-732
Link Following
 Incorrect Permission Assignment for Critical Resource
CVE-2026-42497 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm
1920 9.1 CRITICAL
Network
archive\ \ Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() with… CWE-59
Link Following
CVE-2026-42496 2026-05-28 23:16 2026-05-26 Show GitHub Exploit DB Packet Storm