Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
91 7.2 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるオープンリダイレクトの脆弱性 New CWE-601
オープンリダイレクト
CVE-2026-48895 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
92 5.3 警告
Network
markdown-it project markdown-it markdown-it projectのmarkdown-itにおけるリソースの枯渇に関する脆弱性 New CWE-400
リソースの枯渇
CVE-2026-48988 2026-06-26 11:56 2026-06-17 Show GitHub Exploit DB Packet Storm
93 9.1 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるデータの整合性検証不備に関する脆弱性 New CWE-354
データの整合性検証不備
CVE-2026-49230 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
94 5.4 警告
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるスプーフィングによる認証回避に関する脆弱性 New CWE-290
スプーフィングによる認証回避
CVE-2026-49231 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
95 3.3
Local
pypdf project pypdf pypdf projectのpypdfにおけるアルゴリズムの複雑さに関する脆弱性 New CWE-407
アルゴリズムの複雑性
CVE-2026-49460 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
96 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおけるリソースの枯渇に関する脆弱性 New CWE-400
リソースの枯渇
CVE-2026-49461 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
97 9.8 緊急
Network
litellm litellm LiteLLMにおけるスプーフィングによる認証回避に関する脆弱性 New CWE-290
スプーフィングによる認証回避
CVE-2026-49468 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
98 5.4 警告
Network
Eclipse Foundation Eclipse Open VSX Eclipse FoundationのEclipse Open VSXにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4983 2026-06-26 11:56 2026-06-23 Show GitHub Exploit DB Packet Storm
99 9.3 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-49871 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
100 8.1 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおける認証に関する脆弱性 New CWE-287
不適切な認証
CVE-2026-49872 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
191561 5.4 MEDIUM
Network
wpchill download_monitor Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). CWE-79
Cross-site Scripting
CVE-2021-36920 2024-11-21 15:14 2022-01-15 Show GitHub Exploit DB Packet Storm
191562 4.4 MEDIUM
Local
opensuse factory A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This is… - CVE-2021-36781 2024-11-21 15:14 2022-01-14 Show GitHub Exploit DB Packet Storm
191563 8.8 HIGH
Network
siemens comos A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < … CWE-352
 Origin Validation Error
CVE-2021-37198 2024-11-21 15:14 2022-01-11 Show GitHub Exploit DB Packet Storm
191564 8.8 HIGH
Network
siemens comos A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < … CWE-89
SQL Injection
CVE-2021-37197 2024-11-21 15:14 2022-01-11 Show GitHub Exploit DB Packet Storm
191565 6.1 MEDIUM
Network
siemens comos A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < … CWE-79
Cross-site Scripting
CVE-2021-37195 2024-11-21 15:14 2022-01-11 Show GitHub Exploit DB Packet Storm
191566 6.5 MEDIUM
Network
siemens comos A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >=… CWE-22
Path Traversal
CVE-2021-37196 2024-11-21 15:14 2022-01-11 Show GitHub Exploit DB Packet Storm
191567 6.5 MEDIUM
Network
apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrar… NVD-CWE-noinfo
CVE-2021-36774 2024-11-21 15:14 2022-01-6 Show GitHub Exploit DB Packet Storm
191568 8.1 HIGH
Network
huawei harmonyos Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components. CWE-362
Race Condition
CVE-2021-37134 2024-11-21 15:14 2022-01-4 Show GitHub Exploit DB Packet Storm
191569 7.5 HIGH
Network
huawei magic_ui
emui
harmonyos
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality. NVD-CWE-noinfo
CVE-2021-37133 2024-11-21 15:14 2022-01-4 Show GitHub Exploit DB Packet Storm
191570 5.3 MEDIUM
Network
huawei harmonyos PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of H… CWE-276
Incorrect Default Permissions 
CVE-2021-37132 2024-11-21 15:14 2022-01-4 Show GitHub Exploit DB Packet Storm