Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
133531 4.9 警告
Network
シスコシステムズ Cisco Unified Communications Manager
Cisco Unified Communications Manager IM and Presence Service
複数の Cisco Unified Communications Manager 製品における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2021-1364 2021-10-11 13:47 2021-01-20 Show GitHub Exploit DB Packet Storm
133532 8 重要
Adjacent
Weaveworks Weave Net Weave Net における不要な特権による実行に関する脆弱性 CWE-250
不要な特権による実行
CVE-2020-26278 2021-10-8 18:11 2020-12-17 Show GitHub Exploit DB Packet Storm
133533 5.3 警告
Network
シスコシステムズ Cisco Umbrella 仮想アプライアンス Cisco Umbrella における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2021-1350 2021-10-8 18:11 2021-01-20 Show GitHub Exploit DB Packet Storm
133534 7.8 重要
Local
チェック・ポイント・ソフトウェア・テクノロジーズ SmartConsole Check Point SmartConsole における権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2020-6024 2021-10-8 18:11 2020-01-7 Show GitHub Exploit DB Packet Storm
133535 5.9 警告
Network
STMicroelectronics STM32CubeH7
STM32CubeF2
STM32CubeIDE
STM32CubeF3
STM32CubeF4
STM32CubeF1
STM32CubeF7
STM32CubeF0
STM32CubeG4
STM32CubeG0
STM32Cube デバイスにおける暗号アルゴリズムの使用に関する脆弱性 CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2020-20949 2021-10-8 18:11 2020-08-13 Show GitHub Exploit DB Packet Storm
133536 9.8 緊急
Network
EGavilan Media User Registration & Login System with Admin Panel EgavilanMedia User Registration & Login System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2020-35263 2021-10-8 18:02 2020-11-17 Show GitHub Exploit DB Packet Storm
133537 8.8 重要
Network
Cake Software Foundation CakePHP CakePHP におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2020-35239 2021-10-8 18:02 2020-12-7 Show GitHub Exploit DB Packet Storm
133538 7.5 重要
Network
projectsend.org ProjectSend ProjectSend における認証に関する脆弱性 CWE-287
CWE-404
CVE-2020-28874 2021-10-8 18:02 2020-11-18 Show GitHub Exploit DB Packet Storm
133539 7.8 重要
Local
Debian
OpenJPEG project
OpenJPEG
Debian GNU/Linux
openjpeg2 におけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2020-27814 2021-10-8 18:02 2020-11-26 Show GitHub Exploit DB Packet Storm
133540 6.1 警告
Network
WING FTP software Wing FTP Server Wing FTP におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2020-27735 2021-10-8 18:02 2020-11-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 7.8 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability New CWE-197
 Numeric Truncation Error
CVE-2026-40409 2026-06-12 02:06 2026-06-10 Show GitHub Exploit DB Packet Storm
122 7.5 HIGH
Network
vmware spring_hateoas Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consult… New CWE-284
NVD-CWE-noinfo
Improper Access Control
CVE-2026-41006 2026-06-12 02:05 2026-06-9 Show GitHub Exploit DB Packet Storm
123 7.8 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. New CWE-284
Improper Access Control
CVE-2026-41092 2026-06-12 02:04 2026-06-10 Show GitHub Exploit DB Packet Storm
124 7.0 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. New CWE-122
Heap-based Buffer Overflow
CVE-2026-41108 2026-06-12 02:03 2026-06-10 Show GitHub Exploit DB Packet Storm
125 7.8 HIGH
Local
microsoft windows_11_24h2
windows_11_25h2
windows_11_26h1
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. New CWE-284
Improper Access Control
CVE-2026-42829 2026-06-12 02:02 2026-06-10 Show GitHub Exploit DB Packet Storm
126 7.0 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. New CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2026-42836 2026-06-12 02:01 2026-06-10 Show GitHub Exploit DB Packet Storm
127 7.8 HIGH
Local
microsoft windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2019
windows_server_2022
windows_server_2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. New CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2026-42979 2026-06-12 02:00 2026-06-10 Show GitHub Exploit DB Packet Storm
128 7.5 HIGH
Network
vmware spring_hateoas Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41007 2026-06-12 01:58 2026-06-9 Show GitHub Exploit DB Packet Storm
129 7.8 HIGH
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. New CWE-122
CWE-191
Heap-based Buffer Overflow
 Integer Underflow (Wrap or Wraparound)
CVE-2026-42980 2026-06-12 01:58 2026-06-10 Show GitHub Exploit DB Packet Storm
130 8.1 HIGH
Network
microsoft windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2022
windows_server_2025
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. New CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2026-42981 2026-06-12 01:55 2026-06-10 Show GitHub Exploit DB Packet Storm