Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241811 7.5 危険 netious - Netious CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2461 2012-09-25 17:17 2008-05-27 Show GitHub Exploit DB Packet Storm
241812 7.5 危険 Joomla! - Joomla! 用の com_xsstream-dm コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2454 2012-09-25 17:17 2008-05-27 Show GitHub Exploit DB Packet Storm
241813 4.3 警告 ikemcg - Isaac McGowan phpInstantGallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2449 2012-09-25 17:17 2008-05-27 Show GitHub Exploit DB Packet Storm
241814 7.5 危険 mytipper - e107 用の Mytipper ZoGo-shop プラグインの products.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2447 2012-09-25 17:17 2008-05-27 Show GitHub Exploit DB Packet Storm
241815 9.3 危険 Novell - Novell iPrint Client の nipplib.dll におけるヒープベースのバッファオーバーフローの脆弱性 CWE-94
コード・インジェクション
CVE-2008-2436 2012-09-25 17:17 2008-09-2 Show GitHub Exploit DB Packet Storm
241816 5 警告 Novell - Novell iPrint Client の GetFileList メソッドにおけるイメージファイルを一覧される脆弱性 CWE-200
情報漏えい
CVE-2008-2432 2012-09-25 17:17 2008-11-25 Show GitHub Exploit DB Packet Storm
241817 9.3 危険 Novell - Novell iPrint Client におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2431 2012-09-25 17:17 2008-11-25 Show GitHub Exploit DB Packet Storm
241818 9.3 危険 pagesperso-orange - Nconvert などの製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2427 2012-09-25 17:17 2008-06-24 Show GitHub Exploit DB Packet Storm
241819 10 危険 icdevgroup - Interchange の "標準デモ" 用 404 エラーメッセージにおける脆弱性 CWE-noinfo
情報不足
CVE-2008-2424 2012-09-25 17:17 2008-05-23 Show GitHub Exploit DB Packet Storm
241820 10 危険 interchange development group - Interchange におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-2423 2012-09-25 17:17 2008-05-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
261 7.5 HIGH
Network
wolfssl wolfssl HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signatur… New CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-6331 2026-06-28 04:48 2026-06-26 Show GitHub Exploit DB Packet Storm
262 7.5 HIGH
Network
wolfssl wolfssl PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted. New CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-7511 2026-06-28 04:48 2026-06-26 Show GitHub Exploit DB Packet Storm
263 7.5 HIGH
Network
wolfssl wolfssl iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP addr… New CWE-295
Improper Certificate Validation 
CVE-2026-7532 2026-06-28 04:46 2026-06-26 Show GitHub Exploit DB Packet Storm
264 7.5 HIGH
Network
wolfssl wolfssl wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the … New CWE-354
 Improper Validation of Integrity Check Value
CVE-2026-8720 2026-06-28 04:43 2026-06-26 Show GitHub Exploit DB Packet Storm
265 10.0 CRITICAL
Network
wso2 api_manager The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an at… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-2053 2026-06-28 04:38 2026-06-26 Show GitHub Exploit DB Packet Storm
266 9.8 CRITICAL
Network
jetbrains kotlin In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata New CWE-502
 Deserialization of Untrusted Data
CVE-2026-53914 2026-06-28 04:36 2026-06-26 Show GitHub Exploit DB Packet Storm
267 7.5 HIGH
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint New CWE-862
 Missing Authorization
CVE-2026-57921 2026-06-28 04:35 2026-06-26 Show GitHub Exploit DB Packet Storm
268 5.3 MEDIUM
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible New CWE-862
 Missing Authorization
CVE-2026-57922 2026-06-28 04:33 2026-06-26 Show GitHub Exploit DB Packet Storm
269 7.5 HIGH
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings New CWE-862
 Missing Authorization
CVE-2026-57923 2026-06-28 04:32 2026-06-26 Show GitHub Exploit DB Packet Storm
270 5.3 MEDIUM
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details New CWE-276
Incorrect Default Permissions 
CVE-2026-57924 2026-06-28 04:31 2026-06-26 Show GitHub Exploit DB Packet Storm