Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
133761 7.2 重要
Network
シスコシステムズ RV042G Dual Gigabit WAN VPN ファームウェア
RV016 Multi-WAN VPN ファームウェア
Cisco RV320 Dual Gigabit WAN VPN Router ファームウェア
RV0…
複数の Cisco Small Business RV ルータにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2021-1340 2021-10-18 16:09 2021-02-3 Show GitHub Exploit DB Packet Storm
133762 7.2 重要
Network
シスコシステムズ Cisco RV325 Dual Gigabit WAN VPN Router ファームウェア
RV082 Dual WAN VPN ファームウェア
Cisco RV320 Dual Gigabit WAN VPN …
複数の Cisco Small Business RV ルータにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2021-1341 2021-10-18 15:59 2021-02-3 Show GitHub Exploit DB Packet Storm
133763 7.2 重要
Network
シスコシステムズ Cisco RV325 Dual Gigabit WAN VPN Router ファームウェア
RV082 Dual WAN VPN ファームウェア
Cisco RV320 Dual Gigabit WAN VPN …
複数の Cisco Small Business RV ルータにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2021-1342 2021-10-18 15:54 2021-02-3 Show GitHub Exploit DB Packet Storm
133764 8.8 重要
Adjacent
ADT LifeShield HD Video Doorbell ファームウェア ADT LifeShield DIY HD Video Doorbell におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2020-8101 2021-10-18 15:52 2020-01-28 Show GitHub Exploit DB Packet Storm
133765 9.1 緊急
Network
三菱電機 R08 SFCPU ファームウェア
R16 PSFCPU ファームウェア
R120 PSFCPU ファームウェア
R08 PSFCPU ファームウェア
R120 SFCPU ファームウェア
R32 PSFCPU ファームウェア
R32&nbs…
三菱電機製 MELSEC iQ-R シリーズ CPU ユニットにおける複数の脆弱性 CWE-200
CWE-522
CWE-639
CWE-645
CVE-2021-20594
CVE-2021-20597
CVE-2021-20598
CVE-2021-20599
2021-10-18 15:29 2021-08-5 Show GitHub Exploit DB Packet Storm
133766 - - Apache Software Foundation Apache Tomcat Apache Tomcat におけるサービス運用妨害(DoS)の脆弱性 - CVE-2021-42340 2021-10-18 15:23 2021-10-15 Show GitHub Exploit DB Packet Storm
133767 7.8 重要
Local
Schneider Electric ConneXium Network Manager Schneider Electric 製 ConneXium Network Manager における不適切な権限管理の脆弱性 CWE-269
不適切な権限管理
CVE-2021-22801 2021-10-18 15:18 2021-10-15 Show GitHub Exploit DB Packet Storm
133768 8.8 重要
Network
Belkin International Linksys WRT160NL ファームウェア Belkin Linksys WRT160NL デバイスにおける OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2021-25310 2021-10-18 15:06 2021-01-28 Show GitHub Exploit DB Packet Storm
133769 9.8 緊急
Network
128 Technology 128 Technology Session Smart Router 128 Technology Session Smart Router における認証不備の脆弱性 CWE-287
不適切な認証
CVE-2021-31349 2021-10-18 12:03 2021-10-18 Show GitHub Exploit DB Packet Storm
133770 6.1 警告
Network
Opmantek Open-AudIT Opmantek Open-AudIT におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-3333 2021-10-15 18:10 2021-01-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291 9.8 CRITICAL
Network
- - Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax… New CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-12183 2026-06-14 03:16 2026-06-14 Show GitHub Exploit DB Packet Storm
292 7.6 HIGH
Network
- - SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x b… New CWE-89
SQL Injection
CVE-2026-6428 2026-06-14 02:16 2026-06-14 Show GitHub Exploit DB Packet Storm
293 6.5 MEDIUM
Network
- - Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletio… CWE-645
 Overly Restrictive Account Lockout Mechanism
CVE-2026-53982 2026-06-13 22:16 2026-06-13 Show GitHub Exploit DB Packet Storm
294 7.2 HIGH
Network
- - The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and inclu… CWE-79
Cross-site Scripting
CVE-2026-5513 2026-06-13 21:16 2026-06-13 Show GitHub Exploit DB Packet Storm
295 4.3 MEDIUM
Network
- - The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all vers… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-1291 2026-06-13 19:16 2026-06-13 Show GitHub Exploit DB Packet Storm
296 - - - The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users ha… CWE-346
 Origin Validation Error
CVE-2026-11624 2026-06-13 19:16 2026-06-13 Show GitHub Exploit DB Packet Storm
297 6.4 MEDIUM
Network
- - The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output esca… CWE-79
Cross-site Scripting
CVE-2026-9629 2026-06-13 17:16 2026-06-13 Show GitHub Exploit DB Packet Storm
298 6.4 MEDIUM
Network
- - The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insuf… CWE-79
Cross-site Scripting
CVE-2026-3297 2026-06-13 17:16 2026-06-13 Show GitHub Exploit DB Packet Storm
299 4.3 MEDIUM
Network
- - The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_sav… CWE-863
 Incorrect Authorization
CVE-2026-2470 2026-06-13 17:16 2026-06-13 Show GitHub Exploit DB Packet Storm
300 6.4 MEDIUM
Network
- - The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomple… CWE-79
Cross-site Scripting
CVE-2026-9134 2026-06-13 16:16 2026-06-13 Show GitHub Exploit DB Packet Storm