Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 18, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
221 8.8 重要
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-12289 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
222 5.4 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 New CWE-125
CWE-416
CWE-787
CVE-2026-12298 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
223 5.4 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における型の取り違えに関する脆弱性 New CWE-843
型の取り違え
CVE-2026-12299 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
224 4.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における境界外読み取りに関する脆弱性 New CWE-125
境界外読み取り
CVE-2026-12303 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
225 4.7 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における複数の脆弱性 New CWE-200
CWE-688
CVE-2026-12311 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
226 4.7 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における権限管理に関する脆弱性 New CWE-269
不適切な権限管理
CVE-2026-12313 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
227 6.5 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品におけるリソースの枯渇に関する脆弱性 New CWE-400
リソースの枯渇
CVE-2026-12319 2026-06-17 15:35 2026-06-16 Show GitHub Exploit DB Packet Storm
228 4.3 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における情報漏えいに関する脆弱性 New CWE-200
情報漏えい
CVE-2026-12320 2026-06-17 15:34 2026-06-16 Show GitHub Exploit DB Packet Storm
229 5.4 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品における常に不適切な制御フローの実装に関する脆弱性 New CWE-670
常に不適切な制御フローの実装
CVE-2026-12321 2026-06-17 15:34 2026-06-16 Show GitHub Exploit DB Packet Storm
230 5.4 警告
Network
Mozilla Foundation Mozilla Firefox
Mozilla Thunderbird
Mozilla FoundationのMozilla Firefox等の複数製品におけるレンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限に関する脆弱性 New CWE-1021
レンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限
CVE-2026-12322 2026-06-17 15:34 2026-06-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
309901 - eliteladders elite_gaming_ladders SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter. CWE-89
SQL Injection
CVE-2010-5014 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309902 - mckenziecreations virtual_real_estate_manager SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter. CWE-89
SQL Injection
CVE-2010-5013 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309903 - david_noguera_gutierrez dalogin SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third pa… CWE-89
SQL Injection
CVE-2010-5012 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309904 - schoolmation schoolmation SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter. CWE-89
SQL Injection
CVE-2010-5011 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309905 - schoolmation schoolmation Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter. CWE-79
Cross-site Scripting
CVE-2010-5010 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309906 - ut-files utstats SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action. CWE-89
SQL Injection
CVE-2010-5009 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309907 - denaliintranet brightsuite_groupware SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter. CWE-89
SQL Injection
CVE-2010-5008 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309908 - ut-files utstats Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter. CWE-79
Cross-site Scripting
CVE-2010-5007 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309909 - emophp emo_realty_manager SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter. CWE-89
SQL Injection
CVE-2010-5006 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm
309910 - rayzz photoz Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter… CWE-79
Cross-site Scripting
CVE-2010-5005 2024-11-21 10:22 2011-11-3 Show GitHub Exploit DB Packet Storm