Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2641 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるHTTPS セッション内の Secure 属性がない重要な Cookie に関する脆弱性 CWE-614
HTTPS セッション内の Secure 属性がない重要な Cookie
CVE-2025-52608 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2642 5.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2025-52609 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2643 4.3 警告
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるエラーメッセージによる情報漏えいに関する脆弱性 CWE-209
エラーメッセージによる情報漏えい
CVE-2025-52611 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2644 8.8 重要
Network
HCL Technologies Limited HCL iControl HCL Technologies LimitedのHCL iControlにおけるCSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2025-52612 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2645 7.5 重要
Network
Open JS Foundation Node Version Manager (NVM) Open JS FoundationのNode Version Manager (NVM)におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-10796 2026-06-8 11:49 2026-06-4 Show GitHub Exploit DB Packet Storm
2646 7.8 重要
Local
NVIDIA transformers4rec NVIDIAのtransformers4recにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24162 2026-06-8 11:49 2026-05-26 Show GitHub Exploit DB Packet Storm
2647 7.8 重要
Local
NVIDIA NVTabular NVIDIAのNVTabularにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24221 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
2648 7.8 重要
Local
NVIDIA NVTabular NVIDIAのNVTabularにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-24237 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
2649 6.8 警告
Network
SWUpdate SWUpdate SWUpdateにおける複数の脆弱性 CWE-125
CWE-191
CVE-2026-28525 2026-06-8 11:49 2026-04-23 Show GitHub Exploit DB Packet Storm
2650 7.5 重要
Network
turbo-stream
Shopify
React Router
Turbo Stream
Shopify等の複数ベンダの製品における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-34077 2026-06-8 11:49 2026-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
344531 - e107 e107 Cross-site scripting (XSS) vulnerability in 107_plugins/content/content_manager.php in the Content Management plugin in e107 before 0.7.20, when the personal content manager is enabled, allows user-a… CWE-79
Cross-site Scripting
CVE-2010-0997 2018-10-11 04:55 2010-04-21 Show GitHub Exploit DB Packet Storm
344532 - freedownloadmanager free_download_manager Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-0998 2018-10-11 04:55 2010-05-18 Show GitHub Exploit DB Packet Storm
344533 - freedownloadmanager free_download_manager Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file ele… CWE-22
Path Traversal
CVE-2010-0999 2018-10-11 04:55 2010-05-18 Show GitHub Exploit DB Packet Storm
344534 - kde kde_sc Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in … CWE-22
Path Traversal
CVE-2010-1000 2018-10-11 04:55 2010-05-18 Show GitHub Exploit DB Packet Storm
344535 - kde kde_sc Per: http://www.kde.org/info/security/advisory-20100513-1.txt 'Patches have been committed to the KDE Subversion repository in the following revision numbers: 4.3 branch: r1126227 … CWE-22
Path Traversal
CVE-2010-1000 2018-10-11 04:55 2010-05-18 Show GitHub Exploit DB Packet Storm
344536 - efrontlearning efront Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in th… CWE-22
Path Traversal
CVE-2010-1003 2018-10-11 04:55 2010-03-20 Show GitHub Exploit DB Packet Storm
344537 - hp insight_virtual_machine_management Multiple unspecified vulnerabilities in HP Virtual Machine Manager (VMM) before 6.0 allow remote authenticated users to execute arbitrary code via unknown vectors. NVD-CWE-noinfo
CVE-2010-1035 2018-10-11 04:55 2010-04-23 Show GitHub Exploit DB Packet Storm
344538 - hp
ibm
sgi
nfs\/oncplus
aix
vios
irix
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, an… CWE-134
Use of Externally-Controlled Format String
CVE-2010-1039 2018-10-11 04:55 2010-05-21 Show GitHub Exploit DB Packet Storm
344539 - parscms parscms Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp. CWE-89
SQL Injection
CVE-2010-1054 2018-10-11 04:55 2010-03-24 Show GitHub Exploit DB Packet Storm
344540 - sphere.xlentprojects spherecms SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbitrary SQL commands via encoded null bytes ("%00") in the view parameter, which b… CWE-89
SQL Injection
CVE-2010-1078 2018-10-11 04:55 2010-03-24 Show GitHub Exploit DB Packet Storm