Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233521 6.8 警告 ProjectPier - ProjectPier の index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-5583 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233522 7.5 危険 scssboard - sCssBoard の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5578 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233523 7.5 危険 scssboard - sCssBoard の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-5577 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233524 7.5 危険 scssboard - sCssBoard の admin/forums.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-5576 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233525 7.5 危険 proclanmanager - Pro Clan Manager におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2008-5575 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233526 7.5 危険 unscripts - Webmaster Marketplace の member.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5574 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233527 4.3 警告 phpeppershop - PHPepperShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5569 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233528 4.3 警告 php multiple newsletters - Triangle Solutions PHP Multiple Newsletters の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5566 2012-12-20 18:52 2008-12-15 Show GitHub Exploit DB Packet Storm
233529 5 警告 サン・マイクロシステムズ - Sun Java System Portal Server の Sun Java Web Console コンポーネントにおけるローカルファイルをアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5549 2012-12-20 18:52 2008-12-5 Show GitHub Exploit DB Packet Storm
233530 9.3 危険 VirusBuster - VirusBuster における HTML 文書内のマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5548 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2091 7.8 HIGH
Local
- - Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable i… CWE-428
 Unquoted Search Path or Element
CVE-2021-47985 2026-06-24 00:42 2026-06-20 Show GitHub Exploit DB Packet Storm
2092 7.8 HIGH
Local
- - Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path… CWE-428
 Unquoted Search Path or Element
CVE-2023-54353 2026-06-24 00:42 2026-06-20 Show GitHub Exploit DB Packet Storm
2093 7.1 HIGH
Network
- - gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perf… CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-49338 2026-06-24 00:42 2026-06-20 Show GitHub Exploit DB Packet Storm
2094 8.1 HIGH
Network
- - gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user (i… CWE-22
CWE-697
CWE-732
Path Traversal
 Incorrect Comparison
 Incorrect Permission Assignment for Critical Resource
CVE-2026-49340 2026-06-24 00:42 2026-06-20 Show GitHub Exploit DB Packet Storm
2095 - - - gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulner… CWE-78
OS Command 
CVE-2026-48787 2026-06-24 00:42 2026-06-20 Show GitHub Exploit DB Packet Storm
2096 - - - Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data … CWE-148
CVE-2026-12862 2026-06-24 00:42 2026-06-22 Show GitHub Exploit DB Packet Storm
2097 - - - An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains. CWE-601
Open Redirect
CVE-2026-12863 2026-06-24 00:42 2026-06-22 Show GitHub Exploit DB Packet Storm
2098 7.5 HIGH
Network
- - WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with… CWE-22
Path Traversal
CVE-2026-53779 2026-06-24 00:42 2026-06-23 Show GitHub Exploit DB Packet Storm
2099 9.8 CRITICAL
Network
- - All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into… CWE-94
Code Injection
CVE-2026-12866 2026-06-24 00:42 2026-06-23 Show GitHub Exploit DB Packet Storm
2100 7.8 HIGH
Local
- - AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can e… CWE-428
 Unquoted Search Path or Element
CVE-2025-71326 2026-06-24 00:37 2026-06-20 Show GitHub Exploit DB Packet Storm