Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228401 10 危険 ヒューレット・パッカード - 複数の HP 製品の SNAC registration server におけるファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2013-4811 2013-09-18 14:24 2013-09-9 Show GitHub Exploit DB Packet Storm
228402 10 危険 ヒューレット・パッカード - 複数の HP 製品における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-4809 2013-09-18 14:18 2013-09-9 Show GitHub Exploit DB Packet Storm
228403 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2940 2013-09-18 11:55 2013-09-3 Show GitHub Exploit DB Packet Storm
228404 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2939 2013-09-18 11:55 2013-09-3 Show GitHub Exploit DB Packet Storm
228405 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2938 2013-09-18 11:54 2013-09-3 Show GitHub Exploit DB Packet Storm
228406 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2937 2013-09-18 11:54 2013-09-3 Show GitHub Exploit DB Packet Storm
228407 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2936 2013-09-18 11:53 2013-09-3 Show GitHub Exploit DB Packet Storm
228408 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2935 2013-09-18 11:52 2013-09-3 Show GitHub Exploit DB Packet Storm
228409 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2934 2013-09-18 11:51 2013-09-3 Show GitHub Exploit DB Packet Storm
228410 10 危険 シトリックス・システムズ - Citrix CloudPortal Services Manager における脆弱性 CWE-noinfo
情報不足
CVE-2013-2933 2013-09-18 11:51 2013-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1781 6.5 MEDIUM
Network
- - Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. CWE-77
Command Injection
CVE-2026-42895 2026-06-24 14:17 2026-06-20 Show GitHub Exploit DB Packet Storm
1782 8.1 HIGH
Network
- - OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging t… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-56784 2026-06-24 07:16 2026-06-23 Show GitHub Exploit DB Packet Storm
1783 - - - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784. - CVE-2026-56120 2026-06-24 07:16 2026-06-24 Show GitHub Exploit DB Packet Storm
1784 4.9 MEDIUM
Network
- - The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitizati… CWE-22
Path Traversal
CVE-2026-7547 2026-06-24 06:17 2026-06-19 Show GitHub Exploit DB Packet Storm
1785 5.3 MEDIUM
Network
- - OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel s… CWE-125
Out-of-bounds Read
CVE-2026-56099 2026-06-24 06:17 2026-06-19 Show GitHub Exploit DB Packet Storm
1786 6.5 MEDIUM
Network
- - PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensitive data by registering agents with duplicate IDs. At… CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2026-56077 2026-06-24 06:17 2026-06-19 Show GitHub Exploit DB Packet Storm
1787 7.5 HIGH
Network
- - Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the s… CWE-22
CWE-284
Path Traversal
Improper Access Control
CVE-2026-52844 2026-06-24 06:17 2026-06-24 Show GitHub Exploit DB Packet Storm
1788 6.5 MEDIUM
Network
- - The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-11989 2026-06-24 06:16 2026-06-19 Show GitHub Exploit DB Packet Storm
1789 5.4 MEDIUM
Network
mattermost mattermost_server Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab conne… CWE-862
 Missing Authorization
CVE-2026-5139 2026-06-24 05:50 2026-06-22 Show GitHub Exploit DB Packet Storm
1790 6.4 MEDIUM
Network
mattermost mattermost_server Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscription before applying edits which allows an auth… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-6062 2026-06-24 05:50 2026-06-22 Show GitHub Exploit DB Packet Storm