Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
134501 6.1 警告
Network
マイクロソフト Microsoft Dynamics 365 Microsoft Dynamics 365 Customer Engagement におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-40457 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134502 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server
Microsoft Windows Server におけるセキュリティ機能を回避される脆弱性 CWE-noinfo
情報不足
CVE-2021-40456 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134503 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server&nb…
複数の Microsoft Windows 製品におけるなりすまされる脆弱性 CWE-noinfo
情報不足
CVE-2021-40455 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134504 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft 365 Apps
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Office
Microsoft&nbs…
複数の Microsoft 製品における情報を公開される脆弱性 CWE-312
重要な情報の平文保存
CVE-2021-40454 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134505 7.8 重要
Local
マイクロソフト Microsoft Windows Server
Microsoft Windows Server 2022
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2019
複数の Microsoft Windows 製品における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-40450 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134506 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server&nb…
複数の Microsoft Windows 製品における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-40449 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134507 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server&nb…
複数の Microsoft Windows 製品における権限を昇格される脆弱性 CWE-269
不適切な権限管理
CVE-2021-40443 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134508 9 緊急
Adjacent
マイクロソフト Microsoft Windows 11
Microsoft Windows Server 2022
Microsoft Windows 11 および Windows Server におけるリモートでコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2021-38672 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134509 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server&nb…
複数の Microsoft Windows 製品における情報を公開される脆弱性 CWE-noinfo
情報不足
CVE-2021-38663 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
134510 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2012
Microsoft Windows RT 8.1
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server&nb…
複数の Microsoft Windows 製品における情報を公開される脆弱性 CWE-noinfo
情報不足
CVE-2021-38662 2021-10-22 14:27 2021-10-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 - - - A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted … CWE-1287
 Improper Validation of Specified Type of Input
CVE-2026-10825 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
202 - - - A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems fr… CWE-134
Use of Externally-Controlled Format String
CVE-2026-10828 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
203 - - - A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplie… CWE-121
Stack-based Buffer Overflow
CVE-2026-10829 2026-06-17 00:26 2026-06-16 Show GitHub Exploit DB Packet Storm
204 - - - A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed C… CWE-354
 Improper Validation of Integrity Check Value
CVE-2025-11694 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
205 - - - An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. CWE-362
Race Condition
CVE-2025-13036 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
206 - - - A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including … CWE-862
 Missing Authorization
CVE-2025-14272 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
207 - - - A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing conn… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2026-0646 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
208 - - - An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface passwor… CWE-306
Missing Authentication for Critical Function
CVE-2026-0647 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
209 - - - A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be a… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-11317 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm
210 7.5 HIGH
Network
- - A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell comman… CWE-78
OS Command 
CVE-2026-12398 2026-06-17 00:26 2026-06-17 Show GitHub Exploit DB Packet Storm