Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131551 4.8 警告
Network
X2Engine X2CRM X2engine X2CRM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2020-21088 2021-12-16 11:30 2020-08-13 Show GitHub Exploit DB Packet Storm
131552 9.8 緊急
Network
ShopXO ShopXO Shopxo における権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2020-19778 2021-12-16 11:30 2020-08-13 Show GitHub Exploit DB Packet Storm
131553 8.8 重要
Network
Fedora Project
Nextcloud
Fedora
Nextcloud Desktop Client
Nextcloud Desktop Client におけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2021-22879 2021-12-16 11:30 2021-02-9 Show GitHub Exploit DB Packet Storm
131554 3.3
Local
SUSE s390-tools SUSE Linux Enterprise Server 用 s390-tools における安全でない一時ファイルに関する脆弱性 CWE-377
安全でない一時ファイル
CVE-2021-25316 2021-12-16 11:30 2021-02-25 Show GitHub Exploit DB Packet Storm
131555 9.8 緊急
Network
QNAP Systems Surveillance Station QNAP NAS デバイスにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2021-28797 2021-12-16 11:30 2021-02-17 Show GitHub Exploit DB Packet Storm
131556 9.8 緊急
Network
Facebook Thrift Facebook Thrift における無効なポインタや参照の解放に関する脆弱性 CWE-763
無効なポインタや参照の解放
CVE-2021-24028 2021-12-16 11:30 2021-02-19 Show GitHub Exploit DB Packet Storm
131557 9.8 緊急
Network
Motorola Solutions, Inc MH702x ファームウェア Motorola MH702x デバイスにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2021-3460 2021-12-16 11:30 2021-04-13 Show GitHub Exploit DB Packet Storm
131558 4.9 警告
Network
Perforce Software Helix ALM Perforce Helix ALM における DTD の再帰的なエンティティ参照の不適切な制限に関する脆弱性 CWE-776
DTD の再帰的なエンティティ参照の不適切な制限
CVE-2021-28973 2021-12-16 11:23 2021-04-1 Show GitHub Exploit DB Packet Storm
131559 9.8 緊急
Network
OpenClinic GA OpenClinic GA OpenClinic GA におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2020-27227 2021-12-16 11:10 2020-10-19 Show GitHub Exploit DB Packet Storm
131560 7.5 重要
Network
ASUSTeK Computer Inc.
Asuswrt-Merlin firmware project
RT-AX68U ファームウェア
RT-AX86U ファームウェア
RT-AX58U ファームウェア
RT-AX82U ファームウェア
RT-AX55 ファームウェア
ZenWiFi AX (XT8) ファームウェア
RT-AX56U ファームウェア
RT-AX88…
複数の ASUS ルータ製品のファームウェアにおける過度なイテレーションの脆弱性 CWE-834
過度なイテレーション
CVE-2021-3128 2021-12-16 11:10 2021-04-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 - - - A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted … CWE-1287
 Improper Validation of Specified Type of Input
CVE-2026-10825 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
202 - - - A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems fr… CWE-134
Use of Externally-Controlled Format String
CVE-2026-10828 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
203 - - - A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplie… CWE-121
Stack-based Buffer Overflow
CVE-2026-10829 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
204 - - - A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed C… CWE-354
 Improper Validation of Integrity Check Value
CVE-2025-11694 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
205 - - - An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. CWE-362
Race Condition
CVE-2025-13036 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
206 - - - A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including … CWE-862
 Missing Authorization
CVE-2025-14272 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
207 - - - A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing conn… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-0646 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
208 - - - An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface passwor… CWE-306
Missing Authentication for Critical Function
CVE-2026-0647 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
209 - - - A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be a… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-11317 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
210 7.5 HIGH
Network
- - A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell comman… CWE-78
OS Command 
CVE-2026-12398 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm