Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
134641 7.2 重要
Network
VMware vSphere Replication vSphere Replication におけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2021-21976 2021-11-4 15:01 2021-02-11 Show GitHub Exploit DB Packet Storm
134642 9.8 緊急
Network
Accellion Accellion FTA Accellion における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2021-27101 2021-11-4 15:01 2021-02-16 Show GitHub Exploit DB Packet Storm
134643 4.8 警告
Network
Black Cat Development BlackCat CMS BlackCat CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2021-27237 2021-11-4 15:01 2021-02-16 Show GitHub Exploit DB Packet Storm
134644 7.8 重要
Local
アドビシステムズ Adobe Illustrator Adobe Illustrator における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2021-21053 2021-11-4 15:01 2021-02-9 Show GitHub Exploit DB Packet Storm
134645 7.8 重要
Local
AutoTrace project AutoTrace autotrace における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2019-19005 2021-11-4 15:01 2019-11-15 Show GitHub Exploit DB Packet Storm
134646 5.3 警告
Network
Gotenberg, Inc. Gotenberg gotenberg におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2021-23345 2021-11-4 14:56 2021-02-26 Show GitHub Exploit DB Packet Storm
134647 5.3 警告
Network
VMware Spring Integration Zip Spring-integration-zip におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2021-22114 2021-11-4 14:07 2021-01-28 Show GitHub Exploit DB Packet Storm
134648 5.3 警告
Network
WPServeur WPS Hide Login WPS Hide Login における不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2021-3332 2021-11-4 14:01 2021-02-5 Show GitHub Exploit DB Packet Storm
134649 5.5 警告
Local
GStreamer GStreamer GStreamer における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-3522 2021-11-4 12:41 2021-04-28 Show GitHub Exploit DB Packet Storm
134650 7.5 重要
Network
ssri project ssri ssri における脆弱性 CWE-125
境界外読み取り
CVE-2021-27290 2021-11-4 12:37 2021-01-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
491 8.8 HIGH
Network
jenkins script_security Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attacker… New CWE-693
 Protection Mechanism Failure
CVE-2026-57280 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
492 4.3 MEDIUM
Network
hono hono hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft speci… New CWE-79
Cross-site Scripting
CVE-2026-56761 2026-06-27 04:59 2026-06-24 Show GitHub Exploit DB Packet Storm
493 7.5 HIGH
Network
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP … New CWE-22
Path Traversal
CVE-2026-44017 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm
494 7.5 HIGH
Network
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard … New CWE-776
XML Entity Expansion
CVE-2026-44020 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm
495 5.5 MEDIUM
Local
docling docling Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphic… New CWE-22
Path Traversal
CVE-2026-44022 2026-06-27 04:58 2026-06-25 Show GitHub Exploit DB Packet Storm
496 5.5 MEDIUM
Local
gpac gpac GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_c… New CWE-122
Heap-based Buffer Overflow
CVE-2025-60468 2026-06-27 04:56 2026-06-25 Show GitHub Exploit DB Packet Storm
497 5.3 MEDIUM
Network
fastapiexpert python-multipart Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparentl… New CWE-20
CWE-436
 Improper Input Validation 
 Interpretation Conflict
CVE-2026-53537 2026-06-27 04:54 2026-06-23 Show GitHub Exploit DB Packet Storm
498 3.7 LOW
Network
fastapiexpert python-multipart Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATW… New CWE-436
CWE-444
 Interpretation Conflict
HTTP Request Smuggling
CVE-2026-53538 2026-06-27 04:52 2026-06-23 Show GitHub Exploit DB Packet Storm
499 7.5 HIGH
Network
- - Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host relate… New CWE-476
 NULL Pointer Dereference
CVE-2026-47220 2026-06-27 04:50 2026-06-27 Show GitHub Exploit DB Packet Storm
500 5.9 MEDIUM
Network
- - Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight a… New CWE-416
 Use After Free
CVE-2026-48090 2026-06-27 04:50 2026-06-27 Show GitHub Exploit DB Packet Storm