Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1711 5.3 警告
Network
The Netty project netty-incubator-codec-ohttp Nettyのnetty-incubator-codec-ohttpにおける不十分なランダム値の使用に関する脆弱性 CWE-330
不十分なランダム値の使用
CVE-2026-41207 2026-06-8 12:28 2026-06-4 Show GitHub Exploit DB Packet Storm
1712 9.8 緊急
Network
DragonSoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software DragonSoftのGcb/fcb Government Financial Cybersecurity Configuration Audit Softwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-4312 2026-06-8 12:28 2026-03-17 Show GitHub Exploit DB Packet Storm
1713 5.5 警告
Local
Linaro OP-TEE Trusted FirmwareのOP-TEEにおける型の取り違えに関する脆弱性 CWE-843
型の取り違え
CVE-2026-45702 2026-06-8 12:28 2026-06-3 Show GitHub Exploit DB Packet Storm
1714 9.1 緊急
Network
The Netty project netty-incubator-codec-ohttp Nettyのnetty-incubator-codec-ohttpにおける複数の脆弱性 CWE-125
CWE-787
CVE-2026-48040 2026-06-8 12:28 2026-06-4 Show GitHub Exploit DB Packet Storm
1715 9.8 緊急
Network
マイクロソフト Azure HorizonDB Azure HorizonDB Elevation of Privilege Vulnerability CWE-290
スプーフィングによる認証回避
CVE-2026-48567 2026-06-8 12:28 2026-06-4 Show GitHub Exploit DB Packet Storm
1716 7.5 重要
Network
マイクロソフト Microsoft Exchange Online Microsoft Exchange Online Information Disclosure Vulnerability CWE-285
不適切な認可
CVE-2026-48579 2026-06-8 12:27 2026-06-4 Show GitHub Exploit DB Packet Storm
1717 9.1 緊急
Network
CHORNY Apache::Session::Generate::ModUniqueId CHORNYのApache::Session::Generate::ModUniqueIdにおける予測可能な数字や識別子の生成に関する脆弱性 CWE-340
予測可能な数字や識別子の生成
CVE-2026-5081 2026-06-8 12:27 2026-05-6 Show GitHub Exploit DB Packet Storm
1718 7.1 重要
Adjacent
Securly, Inc. Securly Securly, Inc.のSecurlyにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2026-8874 2026-06-8 12:27 2026-06-3 Show GitHub Exploit DB Packet Storm
1719 7.5 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-8881 2026-06-8 12:27 2026-06-3 Show GitHub Exploit DB Packet Storm
1720 7.5 重要
Network
Securly, Inc. Securly Securly, Inc.のSecurlyにおける複数の脆弱性 CWE-1333
CWE-917
CVE-2026-8888 2026-06-8 12:27 2026-06-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320421 5.4 MEDIUM
Network
rocket.chat rocket.chat The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external acti… CWE-79
Cross-site Scripting
CVE-2024-45621 2024-09-17 02:28 2024-09-3 Show GitHub Exploit DB Packet Storm
320422 5.4 MEDIUM
Network
elabftw elabftw eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript… CWE-79
Cross-site Scripting
CVE-2024-28100 2024-09-17 02:28 2024-09-3 Show GitHub Exploit DB Packet Storm
320423 - - - Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access. CWE-1245
CVE-2024-24968 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320424 - - - Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. CWE-203
 Information Exposure Through Discrepancy
CVE-2024-23984 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320425 - - - Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access. - CVE-2024-23599 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320426 - - - Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. CWE-20
 Improper Input Validation 
CVE-2024-21871 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320427 - - - Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. CWE-20
 Improper Input Validation 
CVE-2024-21829 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320428 - - - Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access. CWE-20
 Improper Input Validation 
CVE-2024-21781 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320429 - - - Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access. CWE-92
 DEPRECATED: Improper Sanitization of Custom Special Characters
CVE-2023-43753 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm
320430 - - - Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. CWE-284
Improper Access Control
CVE-2023-43626 2024-09-17 02:16 2024-09-17 Show GitHub Exploit DB Packet Storm