Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228761 6.8 警告 シスコシステムズ - Cisco Secure Access Control System の管理およびビューページにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-3424 2013-07-16 14:56 2013-07-15 Show GitHub Exploit DB Packet Storm
228762 4.3 警告 シスコシステムズ - Cisco Secure Access Control System の Web インターフェイスにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3423 2013-07-16 14:55 2013-07-15 Show GitHub Exploit DB Packet Storm
228763 4.3 警告 シスコシステムズ - Cisco Secure Access Control System の管理ペ−ジにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3422 2013-07-16 14:54 2013-07-15 Show GitHub Exploit DB Packet Storm
228764 4.3 警告 シスコシステムズ - Cisco Secure Access Control System のヘルプのインデックスページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3421 2013-07-16 14:54 2013-07-15 Show GitHub Exploit DB Packet Storm
228765 4.3 警告 シスコシステムズ - Cisco Unified MeetingPlace Web Conferencing におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3419 2013-07-16 14:53 2013-07-15 Show GitHub Exploit DB Packet Storm
228766 6.8 警告 シスコシステムズ - Cisco Unified Communications Domain Manager におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-3418 2013-07-16 14:51 2013-07-15 Show GitHub Exploit DB Packet Storm
228767 5.4 警告 BlackBerry - QNX Software Development Platform の BlackBerry QNX Neutrino RTOS におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-2688 2013-07-16 14:50 2013-06-4 Show GitHub Exploit DB Packet Storm
228768 7.8 危険 BlackBerry - QNX Software Development Platform におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-2687 2013-07-16 14:49 2013-06-4 Show GitHub Exploit DB Packet Storm
228769 10 危険 IBM
Apache Software Foundation
- IBM WebSphere Application Server などの製品で使用される Apache Geronimo における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-1777 2013-07-16 14:37 2013-07-1 Show GitHub Exploit DB Packet Storm
228770 5 警告 シャープ株式会社 - AQUOSフォトプレーヤー HN-PP150 におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-3655 2013-07-16 14:18 2013-07-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1661 - - - Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, … CWE-178
CWE-307
 Improper Handling of Case Sensitivity
mproper Restriction of Excessive Authentication Attempts
CVE-2026-47203 2026-06-24 01:06 2026-06-20 Show GitHub Exploit DB Packet Storm
1662 - - - Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, … CWE-178
CWE-863
 Improper Handling of Case Sensitivity
 Incorrect Authorization
CVE-2026-48794 2026-06-24 01:06 2026-06-20 Show GitHub Exploit DB Packet Storm
1663 - - - radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When process… CWE-121
Stack-based Buffer Overflow
CVE-2026-48715 2026-06-24 01:04 2026-06-20 Show GitHub Exploit DB Packet Storm
1664 7.5 HIGH
Network
- - Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies … CWE-287
CWE-863
Improper Authentication
 Incorrect Authorization
CVE-2026-50559 2026-06-24 01:04 2026-06-20 Show GitHub Exploit DB Packet Storm
1665 3.2 LOW
Local
- - Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile… CWE-22
CWE-200
Path Traversal
Information Exposure
CVE-2026-49356 2026-06-24 01:04 2026-06-23 Show GitHub Exploit DB Packet Storm
1666 3.1 LOW
Network
- - React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE r… CWE-352
 Origin Validation Error
CVE-2026-53663 2026-06-24 01:04 2026-06-23 Show GitHub Exploit DB Packet Storm
1667 7.1 HIGH
Network
- - libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_pi… CWE-787
 Out-of-bounds Write
CVE-2026-49295 2026-06-24 01:00 2026-06-20 Show GitHub Exploit DB Packet Storm
1668 7.1 HIGH
Network
- - libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow i… CWE-190
 Integer Overflow or Wraparound
CVE-2026-49346 2026-06-24 01:00 2026-06-20 Show GitHub Exploit DB Packet Storm
1669 8.7 HIGH
Network
- - nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an incoming WhatsApp do… CWE-22
Path Traversal
CVE-2026-48716 2026-06-24 00:59 2026-06-19 Show GitHub Exploit DB Packet Storm
1670 - - - OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the tar… CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-49248 2026-06-24 00:59 2026-06-19 Show GitHub Exploit DB Packet Storm