Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242941 7.5 危険 Joomla! - Joomla! 用の NeoRecruit コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-4506 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
242942 7.5 危険 Mambo Foundation
Mambo Communities Pty
- Mambo 用の remository コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-4505 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
242943 5 警告 Joomla! - Joomla! 用の Rsfiles コンポーネントにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-4504 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
242944 7.5 危険 Joomla! - Joomla! 用の Nick Talk コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-4503 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
242945 7.5 危険 Joomla! - Joomla! 用の BibTex コンポーネントの index.php における SQL インジェクションの脆弱性 - CVE-2007-4502 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
242946 7.5 危険 gurur haber - Gurur haber の uyeler2.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4491 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
242947 7.5 危険 linkliste - Linkliste の index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4486 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
242948 7.5 危険 my referer - My_REFERER の login.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4484 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
242949 4.3 警告 マイクロソフト - Microsoft Internet Explorer 6.0 および 7 におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4478 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
242950 9.3 危険 Intuit - Intuit QuickBooks Online Edition ActiveX コントロールにおける任意のファイルを上書きされる脆弱性 CWE-22
CWE-264
CVE-2007-4471 2012-09-25 16:59 2007-09-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1861 7.2 HIGH
Network
misp-project misp MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated… CWE-94
Code Injection
CVE-2026-56446 2026-06-24 01:17 2026-06-22 Show GitHub Exploit DB Packet Storm
1862 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and deter… CWE-200
Information Exposure
CVE-2026-56323 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1863 7.5 HIGH
Network
- - Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allow… CWE-200
Information Exposure
CVE-2026-56322 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1864 8.1 HIGH
Network
- - Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enable… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-56243 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1865 8.2 HIGH
Network
- - Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSo… CWE-862
 Missing Authorization
CVE-2026-56104 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1866 7.5 HIGH
Network
astro astro Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. T… CWE-20
CWE-918
 Improper Input Validation 
Server-Side Request Forgery (SSRF) 
CVE-2026-54299 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1867 5.3 MEDIUM
Network
- - opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. … CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-54285 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1868 - - - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-54277 2026-06-24 01:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1869 - - - Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim aft… CWE-77
CWE-93
Command Injection
CRLF Injection
CVE-2026-47240 2026-06-24 01:16 2026-06-23 Show GitHub Exploit DB Packet Storm
1870 - - - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename,… CWE-502
 Deserialization of Untrusted Data
CVE-2026-45034 2026-06-24 01:16 2026-06-23 Show GitHub Exploit DB Packet Storm