Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131271 8.8 重要
Network
アバイア Avaya Session Border Controller for Enterprise Avaya Session Border Controller for Enterprise における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2020-7034 2021-12-27 11:07 2020-01-14 Show GitHub Exploit DB Packet Storm
131272 5.4 警告
Network
dotCMS dotCMS dotCMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2020-17542 2021-12-27 11:07 2020-08-13 Show GitHub Exploit DB Packet Storm
131273 7.5 重要
Network
MISP project Malware Information Sharing Platform (MISP) MISP における保存または転送前の重要な情報の削除に関する脆弱性 CWE-212
保存または転送前の重要な情報の不適切な削除
CVE-2021-31780 2021-12-27 11:07 2021-04-8 Show GitHub Exploit DB Packet Storm
131274 6.5 警告
Network
Fedora Project
Exiv2 project
Fedora
Exiv2
Exiv2 における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-29470 2021-12-27 11:07 2021-04-23 Show GitHub Exploit DB Packet Storm
131275 8.8 重要
Network
purl project purl purl における脆弱性 CWE-Other
その他
CVE-2021-20089 2021-12-27 11:07 2021-04-23 Show GitHub Exploit DB Packet Storm
131276 8.8 重要
Network
jquery-bbq project jquery-bbq jquery-bbq における脆弱性 CWE-Other
その他
CVE-2021-20086 2021-12-27 11:07 2021-04-23 Show GitHub Exploit DB Packet Storm
131277 8.8 重要
Network
backbone-query-parameters project backbone-query-parameters backbone-query-parameters における脆弱性 CWE-Other
その他
CVE-2021-20085 2021-12-27 11:07 2021-04-23 Show GitHub Exploit DB Packet Storm
131278 8.8 重要
Network
jquery-plugin-query-object project jquery-plugin-query-object jquery-plugin-query-object における脆弱性 CWE-Other
その他
CVE-2021-20083 2021-12-27 11:07 2021-04-23 Show GitHub Exploit DB Packet Storm
131279 7.5 重要
Network
Redis Redis Node-redis における脆弱性 CWE-noinfo
情報不足
CVE-2021-29469 2021-12-27 11:07 2021-04-9 Show GitHub Exploit DB Packet Storm
131280 7.8 重要
Local
Horner Automation Cscape Cscape におけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2021-22682 2021-12-27 11:07 2021-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311 7.5 HIGH
Network
- - A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin… New CWE-416
 Use After Free
CVE-2025-60467 2026-06-27 15:16 2026-06-25 Show GitHub Exploit DB Packet Storm
312 5.0 MEDIUM
Local
- - A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted… New CWE-416
 Use After Free
CVE-2025-60466 2026-06-27 15:16 2026-06-25 Show GitHub Exploit DB Packet Storm
313 6.1 MEDIUM
Local
- - A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … New CWE-416
 Use After Free
CVE-2025-60465 2026-06-27 15:16 2026-06-26 Show GitHub Exploit DB Packet Storm
314 7.2 HIGH
Network
- - A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration… New CWE-863
 Incorrect Authorization
CVE-2026-9640 2026-06-27 14:16 2026-06-27 Show GitHub Exploit DB Packet Storm
315 9.8 CRITICAL
Network
- - Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requ… New CWE-306
CWE-78
Missing Authentication for Critical Function
OS Command 
CVE-2026-49980 2026-06-27 14:16 2026-06-25 Show GitHub Exploit DB Packet Storm
316 7.8 HIGH
Local
freebsd freebsd The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by se… New CWE-123
 Write-what-where Condition
CVE-2026-45257 2026-06-27 14:16 2026-06-27 Show GitHub Exploit DB Packet Storm
317 7.2 HIGH
Network
- - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php,… New CWE-89
SQL Injection
CVE-2026-40083 2026-06-27 14:16 2026-06-26 Show GitHub Exploit DB Packet Storm
318 6.5 MEDIUM
Network
- - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to i… New CWE-89
SQL Injection
CVE-2026-13331 2026-06-27 14:16 2026-06-27 Show GitHub Exploit DB Packet Storm
319 7.5 HIGH
Network
google chrome Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted… New CWE-416
 Use After Free
CVE-2026-13283 2026-06-27 14:16 2026-06-26 Show GitHub Exploit DB Packet Storm
320 8.3 HIGH
Network
google chrome Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chr… New CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-13281 2026-06-27 14:16 2026-06-26 Show GitHub Exploit DB Packet Storm