Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
243191 6.8 警告 pathos - Pathos CMS の warn.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1907 2012-09-25 16:47 2007-04-10 Show GitHub Exploit DB Packet Storm
243192 5.8 警告 jetbox - Jetbox CMS の formmail.php におけるスパムを送信される脆弱性 - CVE-2007-1898 2012-09-25 16:47 2007-05-16 Show GitHub Exploit DB Packet Storm
243193 7.5 危険 The PHP Group - PHP の msg_receive 関数における整数オーバーフローの脆弱性 - CVE-2007-1890 2012-09-25 16:47 2007-03-31 Show GitHub Exploit DB Packet Storm
243194 7.5 危険 The PHP Group - PHP の Zend Memory Manager における整数符号エラーの脆弱性 - CVE-2007-1889 2012-09-25 16:47 2007-03-31 Show GitHub Exploit DB Packet Storm
243195 7.5 危険 The PHP Group - SQLite の src/encode.c におけるバッファオーバーフローの脆弱性 - CVE-2007-1888 2012-09-25 16:47 2007-03-31 Show GitHub Exploit DB Packet Storm
243196 6.8 警告 The PHP Group - PHP における整数オーバーフローの脆弱性 - CVE-2007-1886 2012-09-25 16:47 2007-03-31 Show GitHub Exploit DB Packet Storm
243197 7.5 危険 The PHP Group - PHP の str_replace 関数における整数オーバーフローの脆弱性 - CVE-2007-1885 2012-09-25 16:47 2007-04-5 Show GitHub Exploit DB Packet Storm
243198 6.8 警告 The PHP Group - PHP の printf 関数ファミリにおける整数符号エラーの脆弱性 - CVE-2007-1884 2012-09-25 16:47 2007-04-5 Show GitHub Exploit DB Packet Storm
243199 7.8 危険 The PHP Group - PHP における任意のメモリ領域を読まれる脆弱性 - CVE-2007-1883 2012-09-25 16:47 2007-03-29 Show GitHub Exploit DB Packet Storm
243200 6.5 警告 ヒューレット・パッカード - HP Mercury Quality Center における任意の SQL コマンドを実行される脆弱性 - CVE-2007-1882 2012-09-25 16:47 2007-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1931 9.3 CRITICAL
Network
apache apisix Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by the… CWE-352
 Origin Validation Error
CVE-2026-49871 2026-06-24 00:20 2026-06-19 Show GitHub Exploit DB Packet Storm
1932 8.1 HIGH
Network
apache apisix Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue… CWE-287
Improper Authentication
CVE-2026-49872 2026-06-24 00:18 2026-06-19 Show GitHub Exploit DB Packet Storm
1933 5.4 MEDIUM
Network
apache apisix Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow… CWE-290
 Authentication Bypass by Spoofing
CVE-2026-49231 2026-06-24 00:18 2026-06-19 Show GitHub Exploit DB Packet Storm
1934 9.1 CRITICAL
Network
apache apisix Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue affects Apache API… CWE-354
 Improper Validation of Integrity Check Value
CVE-2026-49230 2026-06-24 00:17 2026-06-19 Show GitHub Exploit DB Packet Storm
1935 6.5 MEDIUM
Network
- - Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email templa… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-39904 2026-06-24 00:17 2026-06-23 Show GitHub Exploit DB Packet Storm
1936 7.2 HIGH
Network
apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session t… CWE-601
Open Redirect
CVE-2026-48895 2026-06-24 00:17 2026-06-19 Show GitHub Exploit DB Packet Storm
1937 9.1 CRITICAL
Network
- - Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using … CWE-338
CWE-340
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
 Generation of Predictable Numbers or Identifiers
CVE-2026-9733 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
1938 5.3 MEDIUM
Network
- - IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized request… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7253 2026-06-24 00:16 2026-06-23 Show GitHub Exploit DB Packet Storm
1939 8.8 HIGH
Network
misp-project misp MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affe… CWE-639
CWE-862
CWE-863
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
 Incorrect Authorization
CVE-2026-56424 2026-06-24 00:16 2026-06-22 Show GitHub Exploit DB Packet Storm
1940 8.8 HIGH
Network
misp-project misp MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level perm… CWE-862
 Missing Authorization
CVE-2026-56423 2026-06-24 00:16 2026-06-22 Show GitHub Exploit DB Packet Storm