Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
134711 7.5 重要
Network
Huawei ManageOne
CampusInsight
Taurus-AL00A ファームウェア
複数の Huawei 製品における HTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2021-22293 2021-10-25 17:30 2021-01-20 Show GitHub Exploit DB Packet Storm
134712 7.5 重要
Network
Huawei eCNS280 ファームウェア eCNS280 におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2021-22292 2021-10-25 17:30 2021-01-13 Show GitHub Exploit DB Packet Storm
134713 6.5 警告
Network
マイクロフォーカス株式会社 Application Performance Management Micro Focus Application Performance Management 製品におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2021-22500 2021-10-25 17:30 2021-02-4 Show GitHub Exploit DB Packet Storm
134714 7.8 重要
Local
Huawei ManageOne
NFV_FusionSphere
iMaster MAE-M
SMC2.0 ファームウェア
複数の Huawei 製品における権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2021-22299 2021-10-25 17:30 2021-01-20 Show GitHub Exploit DB Packet Storm
134715 6.5 警告
Network
Huawei ManageOne Huawei Gauss100 OLTP 製品における脆弱性 CWE-noinfo
情報不足
CVE-2021-22298 2021-10-25 17:30 2021-01-13 Show GitHub Exploit DB Packet Storm
134716 3.3
Local
Huawei Taurus-AL00A ファームウェア Taurus-AL00A における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2021-22303 2021-10-25 17:25 2021-01-27 Show GitHub Exploit DB Packet Storm
134717 4.6 警告
Physics
Huawei Mate 30 ファームウェア Mate 30 における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-22306 2021-10-25 17:21 2021-01-27 Show GitHub Exploit DB Packet Storm
134718 6.8 警告
Physics
Huawei AIS-BW80H-00 ファームウェア AIS-BW80H-00 におけるデータの整合性検証不備に関する脆弱性 CWE-354
データの整合性検証不備
CVE-2020-9118 2021-10-25 16:58 2020-02-18 Show GitHub Exploit DB Packet Storm
134719 4.9 警告
Network
Huawei ManageOne ManageOne における CSV ファイル内の数式要素の中和に関する脆弱性 CWE-1236
CSV ファイル内の数式要素の不適切な中和
CVE-2020-9205 2021-10-25 16:49 2020-02-18 Show GitHub Exploit DB Packet Storm
134720 5.5 警告
Local
シーメンス SIMATIC WinCC
SIMATIC PCS 7
SIMATIC PCS 7 および SIMATIC WinCC における認証に関する脆弱性 CWE-287
不適切な認証
CVE-2020-10048 2021-10-25 16:34 2020-03-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
381 7.8 HIGH
Local
mmaitre314 picklescan picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection… New CWE-502
 Deserialization of Untrusted Data
CVE-2025-71378 2026-06-26 23:12 2026-06-21 Show GitHub Exploit DB Packet Storm
382 9.8 CRITICAL
Network
kidocode crawl4ai Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentic… New CWE-798
 Use of Hard-coded Credentials
CVE-2026-56265 2026-06-26 22:52 2026-06-21 Show GitHub Exploit DB Packet Storm
383 9.1 CRITICAL
Network
imagemagick imagemagick ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on … New CWE-125
Out-of-bounds Read
CVE-2026-56367 2026-06-26 22:50 2026-06-21 Show GitHub Exploit DB Packet Storm
384 8.2 HIGH
Network
imagemagick imagemagick ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during… New CWE-125
Out-of-bounds Read
CVE-2026-56378 2026-06-26 22:41 2026-06-21 Show GitHub Exploit DB Packet Storm
385 7.8 HIGH
Local
langflow langflow A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to … New CWE-74
CWE-94
Injection
Code Injection
CVE-2026-12822 2026-06-26 22:35 2026-06-22 Show GitHub Exploit DB Packet Storm
386 7.5 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacin… New CWE-416
CWE-825
 Use After Free
 Expired Pointer Dereference
CVE-2026-57435 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
387 7.5 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper … New CWE-476
 NULL Pointer Dereference
CVE-2026-57434 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
388 8.2 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a string containing a n… New CWE-416
 Use After Free
CVE-2026-57236 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
389 8.2 HIGH
Network
nokogiri nokogiri Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's… New CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2026-57235 2026-06-26 22:32 2026-06-26 Show GitHub Exploit DB Packet Storm
390 8.1 HIGH
Network
apache doris_mcp_server Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without p… New CWE-89
SQL Injection
CVE-2025-66336 2026-06-26 22:28 2026-06-22 Show GitHub Exploit DB Packet Storm