Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
134341 5.4 警告
Network
new target, inc Custom Global Variables Custom Global Variables におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-3124 2021-11-12 14:18 2021-01-11 Show GitHub Exploit DB Packet Storm
134342 9.8 緊急
Network
yeikos Merge merge パッケージ における脆弱性 CWE-noinfo
情報不足
CVE-2020-28499 2021-11-12 14:18 2020-11-12 Show GitHub Exploit DB Packet Storm
134343 5.3 警告
Network
Containous Traefik Traefik における誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2021-27375 2021-11-12 14:18 2021-02-17 Show GitHub Exploit DB Packet Storm
134344 7.8 重要
Local
Digi International Inc.  ConnectPort X2e ファームウェア Digi ConnectPort X2e におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2020-12878 2021-11-12 14:18 2020-02-13 Show GitHub Exploit DB Packet Storm
134345 7.8 重要
Local
DENX Software Engineering U-Boot Das U-Boot における脆弱性 CWE-noinfo
情報不足
CVE-2021-27138 2021-11-12 14:18 2021-02-16 Show GitHub Exploit DB Packet Storm
134346 7.8 重要
Local
DENX Software Engineering U-Boot Das U-Boot における脆弱性 CWE-noinfo
情報不足
CVE-2021-27097 2021-11-12 14:18 2021-02-16 Show GitHub Exploit DB Packet Storm
134347 8.8 重要
Adjacent
GramAddict GramAddict GramAddict における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2020-36245 2021-11-12 14:18 2020-12-8 Show GitHub Exploit DB Packet Storm
134348 7.4 重要
Network
Canary Mail
libmailcore
MailCore2
Canary Mail
Canary Mail における証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2021-26911 2021-11-12 14:18 2021-02-10 Show GitHub Exploit DB Packet Storm
134349 7.8 重要
Local
アドバンテック株式会社 WebAccess/HMI Advantech 製 WebAccess/HMI Designer に複数の脆弱性 CWE-119
CWE-122
CWE-416
CWE-787
CWE-79
CVE-2021-33000
CVE-2021-33002
CVE-2021-33004
CVE-2021-42703
CVE-2021-42706
2021-11-12 14:12 2021-05-12 Show GitHub Exploit DB Packet Storm
134350 8.8 重要
Network
Fedora Project
Google
Fedora
Google Chrome
Google Chrome のオーディオにおけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2021-21165 2021-11-12 14:10 2021-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
741 9.1 CRITICAL
Network
ibm storage_protect IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hard… CWE-798
 Use of Hard-coded Credentials
CVE-2026-12628 2026-06-27 05:01 2026-06-23 Show GitHub Exploit DB Packet Storm
742 5.5 MEDIUM
Local
rubyconcurrency concurrent_ruby concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The… CWE-128
 Wrap-around Error
CVE-2026-54905 2026-06-27 05:01 2026-06-25 Show GitHub Exploit DB Packet Storm
743 9.8 CRITICAL
Network
rubyconcurrency concurrent_ruby concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with a… CWE-414
CWE-667
 Missing Lock Check
 Improper Locking
CVE-2026-54906 2026-06-27 05:00 2026-06-25 Show GitHub Exploit DB Packet Storm
744 4.8 MEDIUM
Network
jenkins bitbucket_push_and_pull_request Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to th… CWE-295
Improper Certificate Validation 
CVE-2026-57289 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
745 4.3 MEDIUM
Network
jenkins github_branch_source A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers con… CWE-862
 Missing Authorization
CVE-2026-57285 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
746 8.8 HIGH
Network
jenkins script_security Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attacker… CWE-693
 Protection Mechanism Failure
CVE-2026-57280 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
747 4.3 MEDIUM
Network
hono hono hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft speci… CWE-79
Cross-site Scripting
CVE-2026-56761 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
748 7.5 HIGH
Network
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP … CWE-22
Path Traversal
CVE-2026-44017 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm
749 7.5 HIGH
Network
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard … CWE-776
XML Entity Expansion
CVE-2026-44020 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm
750 5.5 MEDIUM
Local
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphic… CWE-22
Path Traversal
CVE-2026-44022 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm