Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
133641 3.3
Local
アドビシステムズ Adobe Acrobat Reader DC
Adobe Acrobat
Adobe Acrobat DC
Adobe Reader および Acrobat における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-21089 2021-10-13 12:26 2021-02-9 Show GitHub Exploit DB Packet Storm
133642 9.1 緊急
Network
日立
json-smart
Hitachi Ops Center Common Services
json-smart-v2
json-smart-v1
netplex json-smart-v1 および json-smart-v2 における例外的な状態のチェックに関する脆弱性 CWE-754
例外的な状態における不適切なチェック
CVE-2021-27568 2021-10-12 18:02 2021-02-23 Show GitHub Exploit DB Packet Storm
133643 7.5 重要
Network
日立
レッドハット
Hitachi Ops Center Common Services
Keycloak
Keycloak における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2021-20222 2021-10-12 18:02 2021-02-3 Show GitHub Exploit DB Packet Storm
133644 7.5 重要
Network
日立
Apache Software Foundation
Hitachi Ops Center Common Services
Apache CXF
Apache CXF におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2021-22696 2021-10-12 18:02 2021-04-2 Show GitHub Exploit DB Packet Storm
133645 5.9 警告
Network
インターネット技術タスクフォース (IETF)
microchip
Microchip Libraries for Applications
Public-Key Cryptography Standards (PKCS) #1
Microchip Libraries for Applications の RSA 用 PKCS #1 パディングにおける暗号アルゴリズムの使用に関する脆弱性 CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2020-20950 2021-10-12 18:02 2020-08-13 Show GitHub Exploit DB Packet Storm
133646 5.4 警告
Network
日立
レッドハット
Hitachi Ops Center Common Services
Keycloak
keycloak における不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2020-1725 2021-10-12 18:02 2019-10-24 Show GitHub Exploit DB Packet Storm
133647 4.3 警告
Network
日立
レッドハット
Hitachi Ops Center Common Services
Red Hat Mobile Application Platform
Red Hat Mobile Aplication Platform におけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2020-1723 2021-10-12 18:02 2019-11-8 Show GitHub Exploit DB Packet Storm
133648 8.8 重要
Network
Mission Labs SmartAgent SmartAgent における重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2021-3165 2021-10-12 17:52 2021-01-12 Show GitHub Exploit DB Packet Storm
133649 6.7 警告
Local
Google Android Android における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2021-0365 2021-10-12 17:33 2021-02-2 Show GitHub Exploit DB Packet Storm
133650 6.7 警告
Local
Google Android Android におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2021-0364 2021-10-12 17:33 2021-02-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 8.2 HIGH
Network
- - The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: P… New CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-50088 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
72 8.2 HIGH
Network
- - The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and h… New CWE-942
 Permissive Cross-domain Policy with Untrusted Domains
CVE-2026-50087 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
73 10.0 CRITICAL
Network
- - The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authenticati… New CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-50086 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
74 8.6 HIGH
Network
- - The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing … New CWE-306
Missing Authentication for Critical Function
CVE-2026-50085 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
75 9.6 CRITICAL
Network
- - The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an e… New CWE-862
 Missing Authorization
CVE-2026-50084 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
76 9.1 CRITICAL
Network
- - The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-50083 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
77 6.5 MEDIUM
Network
- - The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Fun… New CWE-306
Missing Authentication for Critical Function
CVE-2026-50082 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
78 5.3 MEDIUM
Network
- - Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` … New CWE-444
HTTP Request Smuggling
CVE-2026-50020 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
79 4.3 MEDIUM
Network
- - NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metada… New CWE-125
Out-of-bounds Read
CVE-2026-47224 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm
80 9.8 CRITICAL
Network
- - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with a… New CWE-913
 Improper Control of Dynamically-Managed Code Resources
CVE-2026-47210 2026-06-13 02:16 2026-06-13 Show GitHub Exploit DB Packet Storm