|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 26, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 91 | 7.2 |
重要
Network |
Apache Software Foundation | APISIX | Apache Software FoundationのAPISIXにおけるオープンリダイレクトの脆弱性 New |
CWE-601
オープンリダイレクト |
CVE-2026-48895 | 2026-06-26 11:56 | 2026-06-19 | Show | GitHub Exploit DB Packet Storm |
| 92 | 5.3 |
警告
Network |
markdown-it project | markdown-it | markdown-it projectのmarkdown-itにおけるリソースの枯渇に関する脆弱性 New |
CWE-400
リソースの枯渇 |
CVE-2026-48988 | 2026-06-26 11:56 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 93 | 9.1 |
緊急
Network |
Apache Software Foundation | APISIX | Apache Software FoundationのAPISIXにおけるデータの整合性検証不備に関する脆弱性 New |
CWE-354
データの整合性検証不備 |
CVE-2026-49230 | 2026-06-26 11:56 | 2026-06-19 | Show | GitHub Exploit DB Packet Storm |
| 94 | 5.4 |
警告
Network |
Apache Software Foundation | APISIX | Apache Software FoundationのAPISIXにおけるスプーフィングによる認証回避に関する脆弱性 New |
CWE-290
スプーフィングによる認証回避 |
CVE-2026-49231 | 2026-06-26 11:56 | 2026-06-19 | Show | GitHub Exploit DB Packet Storm |
| 95 | 3.3 |
低
Local |
pypdf project | pypdf | pypdf projectのpypdfにおけるアルゴリズムの複雑さに関する脆弱性 New |
CWE-407
アルゴリズムの複雑性 |
CVE-2026-49460 | 2026-06-26 11:56 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 96 | 5.5 |
警告
Local |
pypdf project | pypdf | pypdf projectのpypdfにおけるリソースの枯渇に関する脆弱性 New |
CWE-400
リソースの枯渇 |
CVE-2026-49461 | 2026-06-26 11:56 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 97 | 9.8 |
緊急
Network |
litellm | litellm | LiteLLMにおけるスプーフィングによる認証回避に関する脆弱性 New |
CWE-290
スプーフィングによる認証回避 |
CVE-2026-49468 | 2026-06-26 11:56 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 98 | 5.4 |
警告
Network |
Eclipse Foundation | Eclipse Open VSX | Eclipse FoundationのEclipse Open VSXにおけるクロスサイトスクリプティングの脆弱性 New |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2026-4983 | 2026-06-26 11:56 | 2026-06-23 | Show | GitHub Exploit DB Packet Storm |
| 99 | 9.3 |
緊急
Network |
Apache Software Foundation | APISIX | Apache Software FoundationのAPISIXにおけるクロスサイトリクエストフォージェリの脆弱性 New |
CWE-352
同一生成元ポリシー違反 |
CVE-2026-49871 | 2026-06-26 11:56 | 2026-06-19 | Show | GitHub Exploit DB Packet Storm |
| 100 | 8.1 |
重要
Network |
Apache Software Foundation | APISIX | Apache Software FoundationのAPISIXにおける認証に関する脆弱性 New |
CWE-287
不適切な認証 |
CVE-2026-49872 | 2026-06-26 11:56 | 2026-06-19 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 26, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 190681 | 7.5 |
HIGH
Network |
qualcomm |
apq8009w_firmware apq8017_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware csra6620_firmware csra6640_firmware fsm10055_firmware fsm10056_fir… |
Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indus… |
CWE-125
Out-of-bounds Read |
CVE-2021-35100 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190682 | 6.7 |
MEDIUM
Local |
qualcomm |
apq8053_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware csra6620_firmware csra6640_firmware mdm9150_firmware mdm9640_firmware mdm9650_firmware msm8953_firmware… |
Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial … |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2021-35098 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190683 | 7.5 |
HIGH
Network |
qualcomm |
ar8035_firmware qca6390_firmware qca6391_firmware qca6421_firmware qca6426_firmware qca6431_firmware qca6436_firmware qca6574a_firmware qca6574au_firmware qca6595au_firmwar… |
Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
CWE-770
Allocation of Resources Without Limits or Throttling |
CVE-2021-35096 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190684 | 7.8 |
HIGH
Local |
qualcomm |
aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6421_firmware qca6426_firmware qca6430_firmware qca6431_firmware qca6436_firmware qca6574_firmware | Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Indu… |
CWE-287
Improper Authentication |
CVE-2021-35094 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190685 | 6.7 |
MEDIUM
Local |
qualcomm |
apq8053_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware mdm9150_firmware mdm9650_firmware msm8953_firmware<… |
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co… |
CWE-20
Improper Input Validation |
CVE-2021-35092 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190686 | 7.8 |
HIGH
Local |
qualcomm |
aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6421_firmware qca6426_firmware qca6430_firmware qca6431_firmware qca6436_firmware qcm6490_firmware | Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdrag… |
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition |
CVE-2021-35090 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190687 | 7.5 |
HIGH
Network |
qualcomm |
ar8035_firmware qca6390_firmware qca6391_firmware qca8081_firmware qca8337_firmware qcm6490_firmware qcs6490_firmware sd_8_gen1_5g_firmware sd480_firmware sd690_5g_firmware… |
Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile |
CWE-476
NULL Pointer Dereference |
CVE-2021-35087 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190688 | 7.5 |
HIGH
Network |
qualcomm |
ar8035_firmware qca6390_firmware qca6391_firmware qca6421_firmware qca6426_firmware qca6431_firmware qca6436_firmware qca6574a_firmware qca6574au_firmware qca6595au_firmwar… |
Possible buffer over read due to improper validation of SIB type when processing a NR system Information message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial… |
CWE-125
Out-of-bounds Read |
CVE-2021-35086 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190689 | 7.1 |
HIGH
Local |
qualcomm |
aqt1000_firmware ar8035_firmware csrb31024_firmware qca6175a_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware<… |
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon … |
CWE-125
Out-of-bounds Read |
CVE-2021-35085 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |
| 190690 | 7.1 |
HIGH
Local |
qualcomm |
aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware qca6174a_firmware qca6175a_firmware qca6390_firmware qca6391_firmwar… |
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, S… |
CWE-125
Out-of-bounds Read |
CVE-2021-35084 | 2024-11-21 15:11 | 2022-06-14 | Show | GitHub Exploit DB Packet Storm |