Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131551 7.2 重要
Network
Merit LILIN Ent. Co., Ltd. P2R6552E4 ファームウェア
P2R6352AE4 ファームウェア
P2R6352AE2 ファームウェア
P2G1052 ファームウェア
P2R8852E2 ファームウェア
P2R8852E4 ファームウェア
P2R6552E2 ファームウェア
P2R6852E2 ファ…
複数の Merit LILIN 製品における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2021-30166 2021-12-28 17:27 2021-03-2 Show GitHub Exploit DB Packet Storm
131552 7.5 重要
Network
libexpat project
日立
RV3000
libexpat
libexpat における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2019-15903 2021-12-28 17:00 2019-08-27 Show GitHub Exploit DB Packet Storm
131553 7.5 重要
Network
日立
Expat
RV3000
Expat
Expat における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2018-20843 2021-12-28 16:59 2018-01-11 Show GitHub Exploit DB Packet Storm
131554 7.5 重要
Network
WoWonder WoWonder WoWonder における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2021-26935 2021-12-28 16:53 2021-03-16 Show GitHub Exploit DB Packet Storm
131555 7.5 重要
Network
Kong Kong Gateway Kong Gateway における不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2021-27306 2021-12-28 16:47 2021-02-11 Show GitHub Exploit DB Packet Storm
131556 7.8 重要
Local
apple/swift-format project apple/swift-format Visual Studio Code 用 apple/swift-format extension における脆弱性 CWE-noinfo
情報不足
CVE-2021-28789 2021-12-28 16:29 2021-03-16 Show GitHub Exploit DB Packet Storm
131557 7.8 重要
Local
SwiftLint project SwiftLint Visual Studio Code 用 SwiftLint extension における脆弱性 CWE-noinfo
情報不足
CVE-2021-28790 2021-12-28 16:26 2021-03-16 Show GitHub Exploit DB Packet Storm
131558 6 警告
Local
Parallels parallels desktop Parallels Desktop における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-31430 2021-12-28 16:09 2021-04-14 Show GitHub Exploit DB Packet Storm
131559 8.2 重要
Local
Parallels parallels desktop Parallels Desktop におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2021-31429 2021-12-28 16:09 2021-04-14 Show GitHub Exploit DB Packet Storm
131560 8.2 重要
Local
Parallels parallels desktop Parallels Desktop におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2021-31428 2021-12-28 16:09 2021-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
601 6.5 MEDIUM
Network
wolfssl wolfssl PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the loc… New CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-6329 2026-06-28 04:51 2026-06-26 Show GitHub Exploit DB Packet Storm
602 6.5 MEDIUM
Network
wolfssl wolfssl The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The consta… New CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-6330 2026-06-28 04:50 2026-06-26 Show GitHub Exploit DB Packet Storm
603 7.5 HIGH
Network
wolfssl wolfssl HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signatur… New CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-6331 2026-06-28 04:48 2026-06-26 Show GitHub Exploit DB Packet Storm
604 7.5 HIGH
Network
wolfssl wolfssl PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted. New CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-7511 2026-06-28 04:48 2026-06-26 Show GitHub Exploit DB Packet Storm
605 7.5 HIGH
Network
wolfssl wolfssl iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP addr… New CWE-295
Improper Certificate Validation 
CVE-2026-7532 2026-06-28 04:46 2026-06-26 Show GitHub Exploit DB Packet Storm
606 7.5 HIGH
Network
wolfssl wolfssl wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the … New CWE-354
 Improper Validation of Integrity Check Value
CVE-2026-8720 2026-06-28 04:43 2026-06-26 Show GitHub Exploit DB Packet Storm
607 10.0 CRITICAL
Network
wso2 api_manager The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an at… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-2053 2026-06-28 04:38 2026-06-26 Show GitHub Exploit DB Packet Storm
608 9.8 CRITICAL
Network
jetbrains kotlin In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata New CWE-502
 Deserialization of Untrusted Data
CVE-2026-53914 2026-06-28 04:36 2026-06-26 Show GitHub Exploit DB Packet Storm
609 7.5 HIGH
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint New CWE-862
 Missing Authorization
CVE-2026-57921 2026-06-28 04:35 2026-06-26 Show GitHub Exploit DB Packet Storm
610 5.3 MEDIUM
Network
jetbrains youtrack In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible New CWE-862
 Missing Authorization
CVE-2026-57922 2026-06-28 04:33 2026-06-26 Show GitHub Exploit DB Packet Storm