Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2551 7.5 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-8889 2026-06-8 12:27 2026-06-3 Show GitHub Exploit DB Packet Storm
2552 9.8 緊急
Network
IBM IBM Operations Analytics Log Analysis IBMのIBM Operations Analytics Log Analysisにおける脆弱なパスワードの要求に関する脆弱性 CWE-521
CWE-521
CVE-2024-40684 2026-06-8 12:27 2026-05-27 Show GitHub Exploit DB Packet Storm
2553 8.8 重要
Network
IBM IBM Security QRadar SIEM IBMのIBM Security QRadar SIEMにおける複数の脆弱性 CWE-530
CWE-552
CVE-2024-56462 2026-06-8 12:27 2026-05-27 Show GitHub Exploit DB Packet Storm
2554 9.8 緊急
Network
Python Software Foundation Python Python Software FoundationのPythonにおける複数の脆弱性 CWE-20
CWE-434
CWE-74
CVE-2025-13462 2026-06-8 12:27 2026-03-12 Show GitHub Exploit DB Packet Storm
2555 6.1 警告
Network
Forcepoint LLC. Forcepoint Web Security Forcepoint LLC.のForcepoint Web Securityにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-2274 2026-06-8 12:27 2026-03-16 Show GitHub Exploit DB Packet Storm
2556 6.4 警告
Local
レッドハット Red Hat Fuse レッドハットのRed Hat Fuseにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-57849 2026-06-8 12:27 2026-03-13 Show GitHub Exploit DB Packet Storm
2557 9.8 緊急
Network
HCL Technologies Limited unica
HCL Unica Audience Central
HCL Technologies Limitedのunica等の複数製品におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-62319 2026-06-8 12:27 2026-03-16 Show GitHub Exploit DB Packet Storm
2558 6.4 警告
Local
レッドハット Red Hat OpenShift Data Foundation レッドハットのRed Hat OpenShift Data Foundationにおける不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-8766 2026-06-8 12:27 2026-03-13 Show GitHub Exploit DB Packet Storm
2559 8.8 重要
Network
Amazon.com, Inc. Kiro IDE Amazon.com, Inc.のKiro IDEにおける重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2026-10591 2026-06-8 12:27 2026-06-2 Show GitHub Exploit DB Packet Storm
2560 4.3 警告
Network
MISP MISP MISPにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-10854 2026-06-8 12:27 2026-06-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311101 - adobe flash_player Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly handle unspecified encodings during the parsing o… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3636 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311102 - justsystems ichitaro Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3915. NVD-CWE-noinfo
CVE-2010-3916 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311103 - justsystems ichitaro Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3916. NVD-CWE-noinfo
CVE-2010-3915 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311104 - redhat luci The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authen… CWE-287
Improper Authentication
CVE-2010-3852 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311105 - poppler
foolabs
kde
glyphandcog
poppler
xpdf
kdegraphics
xpdfreader
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows co… CWE-20
 Improper Input Validation 
CVE-2010-3704 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311106 - poppler poppler The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dep… CWE-20
 Improper Input Validation 
CVE-2010-3703 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311107 - freedesktop
xpdfreader
apple
fedoraproject
opensuse
suse
debian
redhat
canonical
poppler
xpdf
cups
fedora
opensuse
linux_enterprise_server
debian_linux
enterprise_linux_server
enterprise_linux_workstation
enterprise_linux_desktop
ubuntu_linux
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent atta… CWE-476
 NULL Pointer Dereference
CVE-2010-3702 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311108 - transware active\!_mail CRLF injection vulnerability in TransWARE Active! mail 6 build 6.40.010047750 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unsp… CWE-94
Code Injection
CVE-2010-3913 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311109 - jsecurity
apache
jsecurity
shiro
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restric… CWE-22
Path Traversal
CVE-2010-3863 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm
311110 - nongnu cvs Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based bu… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3846 2024-11-21 10:19 2010-11-6 Show GitHub Exploit DB Packet Storm