Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
246551 7.5 危険 GForge Group - GForge における SQL インジェクションの脆弱性 CWE-20
CWE-89
CVE-2007-3913 2012-06-26 15:54 2007-09-6 Show GitHub Exploit DB Packet Storm
246552 7.2 危険 Debian - debian-goodies の checkrestart における権限を取得される脆弱性 CWE-20
CWE-264
CVE-2007-3912 2012-06-26 15:54 2007-09-1 Show GitHub Exploit DB Packet Storm
246553 10 危険 bakbone - BakBone NetVault Reporter の clsscheduler.exe におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-3911 2012-06-26 15:54 2007-07-30 Show GitHub Exploit DB Packet Storm
246554 4.3 警告 bandersnatch - Bandersnatch におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3910 2012-06-26 15:54 2007-07-19 Show GitHub Exploit DB Packet Storm
246555 7.5 危険 bandersnatch - Bandersnatch における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-3909 2012-06-26 15:54 2007-07-19 Show GitHub Exploit DB Packet Storm
246556 4.3 警告 asp ziyaretci defteri - ASP Ziyaretci Defteri の mesaj_formu.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3887 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
246557 4.3 警告 ASP indir - husrevforum の philboard_search.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3885 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
246558 7.5 危険 ASP indir - husrevforum の philboard_forum.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-3884 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
246559 5.1 警告 datadynamics - Data Dynamics ActiveBar ActiveX コントロールにおけるファイルを作成される脆弱性 - CVE-2007-3883 2012-06-26 15:54 2007-07-18 Show GitHub Exploit DB Packet Storm
246560 4.3 警告 CA Technologies - CA Anti-Virus などの arclib.dll におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3875 2012-06-26 15:54 2007-07-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
751 9.8 CRITICAL
Network
joomla joomla\! An improper validation of user-supplied input leads to a local file inclusion vulnerability. New CWE-22
Path Traversal
CVE-2026-40383 2026-05-27 21:24 2026-05-27 Show GitHub Exploit DB Packet Storm
752 7.5 HIGH
Network
microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. New CWE-269
 Improper Privilege Management
CVE-2026-23663 2026-05-27 21:16 2026-05-23 Show GitHub Exploit DB Packet Storm
753 10.0 CRITICAL
Network
microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. New CWE-346
 Origin Validation Error
CVE-2026-42901 2026-05-27 21:13 2026-05-23 Show GitHub Exploit DB Packet Storm
754 - - - The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. New CWE-284
Improper Access Control
CVE-2026-48906 2026-05-27 20:16 2026-05-27 Show GitHub Exploit DB Packet Storm
755 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11… New CWE-89
SQL Injection
CVE-2026-8054 2026-05-27 18:16 2026-05-27 Show GitHub Exploit DB Packet Storm
756 9.1 CRITICAL
Network
- - Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo… New CWE-284
Improper Access Control
CVE-2026-49002 2026-05-27 18:16 2026-05-27 Show GitHub Exploit DB Packet Storm
757 5.3 MEDIUM
Network
- - Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe… New CWE-352
 Origin Validation Error
CVE-2026-49001 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
758 7.0 HIGH
Network
- - An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag… New CWE-310
Cryptographic Issues
CVE-2026-49000 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
759 5.7 MEDIUM
Network
- - Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo… New CWE-79
Cross-site Scripting
CVE-2026-48999 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm
760 - - - IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/… New CWE-755
 Improper Handling of Exceptional Conditions
CVE-2026-48961 2026-05-27 17:16 2026-05-27 Show GitHub Exploit DB Packet Storm