Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
132911 7.5 重要
Network
HR Portal project HR Portal HR Portal of Soar Cloud System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2021-22854 2021-11-9 15:15 2021-02-18 Show GitHub Exploit DB Packet Storm
132912 5.4 警告
Network
HR Portal project HR Portal HR Portal of Soar Cloud System における権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2021-22853 2021-11-9 15:15 2021-02-18 Show GitHub Exploit DB Packet Storm
132913 6.5 警告
Local
Xen プロジェクト
Debian
Linux
Linux Kernel
Debian GNU/Linux
Xen
Xen PV で使用される Linux Kernel における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2021-28038 2021-11-9 14:47 2021-03-4 Show GitHub Exploit DB Packet Storm
132914 4.9 警告
Network
Magento, Inc. UPWAR-php
UPWARD Connector
Magento UPWARD-php および Magento UPWARD Connector におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2021-21064 2021-11-9 14:31 2021-02-23 Show GitHub Exploit DB Packet Storm
132915 8.8 重要
Network
png-img png-img png-img における整数オーバーフローの脆弱性 CWE-190
CWE-787
CVE-2020-28248 2021-11-9 14:31 2020-10-6 Show GitHub Exploit DB Packet Storm
132916 6.1 警告
Network
Google slashify Node.js 用 slashify パッケージにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2021-3189 2021-11-9 14:31 2021-01-20 Show GitHub Exploit DB Packet Storm
132917 8.8 重要
Network
SmartStore AG SmartStoreNET SmartStoreNET におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2020-27997 2021-11-9 14:31 2020-07-15 Show GitHub Exploit DB Packet Storm
132918 8.8 重要
Network
Mailtrain Mailtrain Mailtrain における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2020-24617 2021-11-9 14:31 2020-07-13 Show GitHub Exploit DB Packet Storm
132919 5.9 警告
Network
twitter-stream twitter-stream voloko twitter-stream における証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2020-24392 2021-11-9 14:31 2020-09-22 Show GitHub Exploit DB Packet Storm
132920 8.8 重要
Network
Atlassian Alfresco Enterprise Content Management Alfresco Enterprise Content Management におけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2020-12873 2021-11-9 14:31 2020-07-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1241 5.5 MEDIUM
Local
nsa ghidra Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names… CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-52753 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
1242 5.7 MEDIUM
Adjacent
microsoft windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2022
windows_server_2025
Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network. CWE-131
Incorrect Calculation of Buffer Size
CVE-2026-42915 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
1243 7.8 HIGH
Local
nsa ghidra Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with travers… CWE-22
Path Traversal
CVE-2026-52752 2026-06-12 04:52 2026-06-10 Show GitHub Exploit DB Packet Storm
1244 8.8 HIGH
Network
nsa ghidra Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a maliciou… CWE-502
 Deserialization of Untrusted Data
CVE-2026-52751 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
1245 5.3 MEDIUM
Network
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Windows Kerberos Denial of Service Vulnerability CWE-125
Out-of-bounds Read
CVE-2026-42914 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
1246 7.8 HIGH
Local
nsa ghidra Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands und… CWE-88
Argument Injection
CVE-2026-52750 2026-06-12 04:51 2026-06-10 Show GitHub Exploit DB Packet Storm
1247 8.8 HIGH
Network
nsa ghidra Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE … CWE-89
SQL Injection
CVE-2026-49498 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm
1248 3.3 LOW
Local
nsa ghidra Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attacke… CWE-22
Path Traversal
CVE-2026-49497 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm
1249 6.1 MEDIUM
Local
nsa ghidra Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vecto… CWE-416
 Use After Free
CVE-2026-49496 2026-06-12 04:50 2026-06-10 Show GitHub Exploit DB Packet Storm
1250 5.5 MEDIUM
Local
nsa ghidra Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O b… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-49495 2026-06-12 04:49 2026-06-10 Show GitHub Exploit DB Packet Storm