Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131311 7.5 重要
Network
マイクロソフト Microsoft Defender for IoT Microsoft Defender for IoT における情報を公開される脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2021-43888 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131312 7.5 重要
Network
マイクロソフト Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windo…
複数の Microsoft Windows における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-43893 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131313 7.8 重要
Local
マイクロソフト Visual Studio Code Visual Studio Code におけるリモートでコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2021-43891 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131314 7.8 重要
Local
マイクロソフト Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windo…
複数の Microsoft Windows 製品における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-43883 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131315 9.8 緊急
Network
マイクロソフト Microsoft Defender for IoT Microsoft Defender for IoT におけるリモートでコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2021-43882 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131316 6.1 警告
Local
マイクロソフト Microsoft Windows 11 Microsoft Windows 11 における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-43880 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131317 7.8 重要
Local
マイクロソフト ASP.NET Core
Microsoft Visual Studio
ASP.NET Core および Microsoft Visual Studio における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-43877 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131318 7.8 重要
Local
マイクロソフト Microsoft Office
Microsoft 365 Apps
Microsoft 365 Apps および Office におけるリモートでコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2021-43875 2021-12-24 16:35 2021-12-14 Show GitHub Exploit DB Packet Storm
131319 7.8 重要
Local
マイクロソフト Microsoft Windows 11
Microsoft Windows 7
Microsoft Windows RT 8.1
Microsoft Windows Server 2019
Microsoft Windows Server
Mic…
複数の Microsoft Windows 製品における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-43226 2021-12-24 15:13 2021-12-14 Show GitHub Exploit DB Packet Storm
131320 9.8 緊急
Network
マイクロソフト Bot Framework SDK Bot Framework SDK におけるリモートでコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2021-43225 2021-12-24 15:13 2021-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
381 7.8 HIGH
Local
mmaitre314 picklescan picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection… New CWE-502
 Deserialization of Untrusted Data
CVE-2025-71378 2026-06-26 23:12 2026-06-21 Show GitHub Exploit DB Packet Storm
382 9.8 CRITICAL
Network
kidocode crawl4ai Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentic… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-56265 2026-06-26 22:52 2026-06-21 Show GitHub Exploit DB Packet Storm
383 9.1 CRITICAL
Network
imagemagick imagemagick ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on … New CWE-125
Out-of-bounds Read
CVE-2026-56367 2026-06-26 22:50 2026-06-21 Show GitHub Exploit DB Packet Storm
384 8.2 HIGH
Network
imagemagick imagemagick ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during… New CWE-125
Out-of-bounds Read
CVE-2026-56378 2026-06-26 22:41 2026-06-21 Show GitHub Exploit DB Packet Storm
385 7.8 HIGH
Local
langflow langflow A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to … New CWE-74
CWE-94
Injection
Code Injection
CVE-2026-12822 2026-06-26 22:35 2026-06-22 Show GitHub Exploit DB Packet Storm
386 7.5 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacin… New CWE-416
CWE-825
 Use After Free
 Expired Pointer Dereference
CVE-2026-57435 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
387 7.5 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper … New CWE-476
 NULL Pointer Dereference
CVE-2026-57434 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
388 8.2 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a string containing a n… New CWE-416
 Use After Free
CVE-2026-57236 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
389 8.2 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's… New CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2026-57235 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
390 8.1 HIGH
Network
apache doris_mcp_server Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without p… New CWE-89
SQL Injection
CVE-2025-66336 2026-06-26 22:28 2026-06-22 Show GitHub Exploit DB Packet Storm