Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228381 4.3 警告 マイクロソフト - Microsoft Internet Explorer 6 から 10 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3192 2013-08-15 15:48 2013-08-13 Show GitHub Exploit DB Packet Storm
228382 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 および 10 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3191 2013-08-15 15:46 2013-08-13 Show GitHub Exploit DB Packet Storm
228383 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 から 10 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3190 2013-08-15 15:45 2013-08-13 Show GitHub Exploit DB Packet Storm
228384 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 および 9 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3189 2013-08-15 15:44 2013-08-13 Show GitHub Exploit DB Packet Storm
228385 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 および 9 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3188 2013-08-15 15:43 2013-08-13 Show GitHub Exploit DB Packet Storm
228386 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 および 10 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3187 2013-08-15 15:41 2013-08-13 Show GitHub Exploit DB Packet Storm
228387 7.6 危険 マイクロソフト - Microsoft Internet Explorer 7 から 10 の保護モード機能における特権の昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3186 2013-08-15 15:39 2013-08-13 Show GitHub Exploit DB Packet Storm
228388 5 警告 マイクロソフト - Microsoft Active Directory フェデレーションサービスにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-3185 2013-08-15 15:38 2013-08-13 Show GitHub Exploit DB Packet Storm
228389 9.3 危険 マイクロソフト - Microsoft Internet Explorer 7 から 10 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3184 2013-08-15 15:36 2013-08-13 Show GitHub Exploit DB Packet Storm
228390 7.8 危険 マイクロソフト - 複数の Microsoft Windows 製品の TCP/IP の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-3183 2013-08-15 15:35 2013-08-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1631 6.5 MEDIUM
Local
libexpat_project libexpat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. CWE-190
 Integer Overflow or Wraparound
CVE-2026-56409 2026-06-24 01:21 2026-06-22 Show GitHub Exploit DB Packet Storm
1632 6.9 MEDIUM
Local
libexpat_project libexpat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. CWE-190
 Integer Overflow or Wraparound
CVE-2026-56410 2026-06-24 01:18 2026-06-22 Show GitHub Exploit DB Packet Storm
1633 7.4 HIGH
Local
- - pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor. CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-56815 2026-06-24 01:17 2026-06-24 Show GitHub Exploit DB Packet Storm
1634 6.5 MEDIUM
Network
- - Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simple… CWE-611
XXE
CVE-2026-56701 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1635 7.2 HIGH
Network
misp-project misp MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated… CWE-94
Code Injection
CVE-2026-56446 2026-06-24 01:17 2026-06-22 Show GitHub Exploit DB Packet Storm
1636 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and deter… CWE-200
Information Exposure
CVE-2026-56323 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1637 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allow… CWE-200
Information Exposure
CVE-2026-56322 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1638 8.1 HIGH
Network
- - Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enable… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-56243 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1639 8.2 HIGH
Network
- - Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSo… CWE-862
 Missing Authorization
CVE-2026-56104 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1640 7.5 HIGH
Network
astro astro Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. T… CWE-20
CWE-918
 Improper Input Validation 
Server-Side Request Forgery (SSRF) 
CVE-2026-54299 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm