Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
91 8.1 重要
Network
Apache Software Foundation Apache Doris-MCP-Server Apache Software FoundationのApache Doris-MCP-ServerにおけるSQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2025-66336 2026-06-29 11:21 2026-06-22 Show GitHub Exploit DB Packet Storm
92 8.8 重要
Network
flowiseai flowise flowiseaiのflowiseにおけるSQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2025-71332 2026-06-29 11:21 2026-06-24 Show GitHub Exploit DB Packet Storm
93 7.8 重要
Local
Matthieu Maitre Picklescan Matthieu MaitreのPicklescanにおける信頼できないデータのデシリアライゼーションに関する脆弱性 New CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-71348 2026-06-29 11:21 2026-06-21 Show GitHub Exploit DB Packet Storm
94 7.8 重要
Local
Matthieu Maitre Picklescan Matthieu MaitreのPicklescanにおける信頼できないデータのデシリアライゼーションに関する脆弱性 New CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-71357 2026-06-29 11:21 2026-06-21 Show GitHub Exploit DB Packet Storm
95 7.8 重要
Local
Matthieu Maitre Picklescan Matthieu MaitreのPicklescanにおける信頼できないデータのデシリアライゼーションに関する脆弱性 New CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-71378 2026-06-29 11:21 2026-06-21 Show GitHub Exploit DB Packet Storm
96 7.5 重要
Network
vLLM vLLM vLLMにおける非効率的な正規表現の複雑さに関する脆弱性 New CWE-1333
非効率的な正規表現の複雑さ
CVE-2025-71379 2026-06-29 11:21 2026-06-20 Show GitHub Exploit DB Packet Storm
97 6.5 警告
Network
Artifex Software MuPDF Artifex SoftwareのMuPDFにおける再帰制御に関する脆弱性 New CWE-674
不適切な再帰制御
CVE-2025-71382 2026-06-29 11:21 2026-06-23 Show GitHub Exploit DB Packet Storm
98 3.8
Network
GitLab.org GitLab GitLab.orgのGitLabにおける不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2026-0934 2026-06-29 11:21 2026-06-25 Show GitHub Exploit DB Packet Storm
99 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-10086 2026-06-29 11:21 2026-06-25 Show GitHub Exploit DB Packet Storm
100 10 緊急
Network
langflow langflow langflowにおけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2026-10561 2026-06-29 11:21 2026-06-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
190601 5.3 MEDIUM
Network
ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could explo… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2021-38879 2024-11-21 15:18 2022-06-25 Show GitHub Exploit DB Packet Storm
190602 5.4 MEDIUM
Network
ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in… CWE-79
Cross-site Scripting
CVE-2021-38871 2024-11-21 15:18 2022-06-25 Show GitHub Exploit DB Packet Storm
190603 6.1 MEDIUM
Network
ibm
netapp
planning_analytics
cognos_analytics
oncommand_insight
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… CWE-79
Cross-site Scripting
CVE-2021-39047 2024-11-21 15:18 2022-06-25 Show GitHub Exploit DB Packet Storm
190604 9.8 CRITICAL
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-38945 2024-11-21 15:18 2022-06-25 Show GitHub Exploit DB Packet Storm
190605 5.3 MEDIUM
Network
ibm qradar_wincollect IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549. NVD-CWE-noinfo
CVE-2021-39006 2024-11-21 15:18 2022-06-22 Show GitHub Exploit DB Packet Storm
190606 5.4 MEDIUM
Network
ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… CWE-79
Cross-site Scripting
CVE-2021-39043 2024-11-21 15:18 2022-05-21 Show GitHub Exploit DB Packet Storm
190607 6.1 MEDIUM
Network
ibm datapower_gateway IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS… CWE-79
Cross-site Scripting
CVE-2021-38944 2024-11-21 15:18 2022-05-19 Show GitHub Exploit DB Packet Storm
190608 7.5 HIGH
Network
ibm datapower_gateway IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple req… NVD-CWE-noinfo
CVE-2021-38872 2024-11-21 15:18 2022-05-18 Show GitHub Exploit DB Packet Storm
190609 5.4 MEDIUM
Network
ibm jazz_foundation IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U… CWE-79
Cross-site Scripting
CVE-2021-39059 2024-11-21 15:18 2022-05-12 Show GitHub Exploit DB Packet Storm
190610 9.8 CRITICAL
Network
ibm spectrum_virtualize IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609. CWE-798
 Use of Hard-coded Credentials
CVE-2021-38969 2024-11-21 15:18 2022-05-12 Show GitHub Exploit DB Packet Storm