Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227991 5 警告 Moodle - Moodle の blog/rsslib.php における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-6105 2013-01-29 16:54 2013-01-21 Show GitHub Exploit DB Packet Storm
227992 5 警告 Moodle - Moodle の blog/rsslib.php における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-6104 2013-01-29 16:54 2013-01-21 Show GitHub Exploit DB Packet Storm
227993 6.8 警告 Moodle - Moodle の messaging システムにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6103 2013-01-29 16:53 2013-01-21 Show GitHub Exploit DB Packet Storm
227994 6.4 警告 Moodle - Moodle における任意のユーザのサブミッションコメントを読まれるまたは改ざんされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6102 2013-01-29 16:53 2013-01-21 Show GitHub Exploit DB Packet Storm
227995 4.3 警告 Moodle - Moodle におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2012-6101 2013-01-29 16:52 2013-01-21 Show GitHub Exploit DB Packet Storm
227996 4 警告 Moodle - Moodle の report/outline/index.php における隠し最終アクセス値を見つけられる脆弱性 CWE-200
情報漏えい
CVE-2012-6100 2013-01-29 16:52 2013-01-21 Show GitHub Exploit DB Packet Storm
227997 4 警告 Moodle - Moodle の backup/converter/moodle1/lib.php における任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-6099 2013-01-29 16:51 2013-01-21 Show GitHub Exploit DB Packet Storm
227998 4 警告 Moodle - Moodle におけるカスタム結果を標準のサイト全体の成果に変換される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6098 2013-01-29 16:51 2013-01-21 Show GitHub Exploit DB Packet Storm
227999 5 警告 General Electric Company - GE Intelligent Platforms Proficy Real-Time Information Portal におけるユーザ名のリストを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0652 2013-01-29 16:49 2013-01-22 Show GitHub Exploit DB Packet Storm
228000 5 警告 General Electric Company - GE Intelligent Platforms Proficy Real-Time Information Portal における設定ファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0651 2013-01-29 16:48 2013-01-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
431 6.1 MEDIUM
Network
- - HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser. New CWE-79
Cross-site Scripting
CVE-2026-21825 2026-06-6 01:05 2026-06-5 Show GitHub Exploit DB Packet Storm
432 6.1 MEDIUM
Network
- - HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected … New CWE-601
Open Redirect
CVE-2026-21826 2026-06-6 01:05 2026-06-5 Show GitHub Exploit DB Packet Storm
433 - - - HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the… New CWE-78
OS Command 
CVE-2026-21837 2026-06-6 01:05 2026-06-5 Show GitHub Exploit DB Packet Storm
434 - - - A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. New CWE-284
Improper Access Control
CVE-2026-48907 2026-06-6 01:05 2026-06-5 Show GitHub Exploit DB Packet Storm
435 6.3 MEDIUM
Network
- - Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating… New CWE-79
Cross-site Scripting
CVE-2025-65640 2026-06-6 01:04 2026-06-5 Show GitHub Exploit DB Packet Storm
436 5.3 MEDIUM
Network
- - HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client … New CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2020-25900 2026-06-6 01:04 2026-06-6 Show GitHub Exploit DB Packet Storm
437 - - - Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parame… New - CVE-2026-38579 2026-06-6 01:04 2026-06-6 Show GitHub Exploit DB Packet Storm
438 6.3 MEDIUM
Network
- - A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted element is an unkno… New CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-11333 2026-06-6 01:04 2026-06-6 Show GitHub Exploit DB Packet Storm
439 7.3 HIGH
Network
- - A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file d… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-11334 2026-06-6 01:04 2026-06-6 Show GitHub Exploit DB Packet Storm
440 6.3 MEDIUM
Network
- - A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /… New CWE-384
 Session Fixation
CVE-2026-11335 2026-06-6 01:04 2026-06-6 Show GitHub Exploit DB Packet Storm