|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 27, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 181 | 7.1 |
重要
Network |
Jenkins プロジェクト | Assembla | JenkinsのAssemblaにおけるサーバサイドのリクエストフォージェリの脆弱性 New |
CWE-918
サーバサイドリクエストフォージェリ |
CVE-2026-57303 | 2026-06-26 11:52 | 2026-06-24 | Show | GitHub Exploit DB Packet Storm |
| 182 | 5.4 |
警告
Network |
Jenkins プロジェクト | Assembla | JenkinsのAssemblaにおける認証の欠如に関する脆弱性 New |
CWE-862
認証の欠如 |
CVE-2026-57304 | 2026-06-26 11:52 | 2026-06-24 | Show | GitHub Exploit DB Packet Storm |
| 183 | 5.4 |
警告
Network |
Jenkins プロジェクト | Assembla | JenkinsのAssemblaにおけるクロスサイトリクエストフォージェリの脆弱性 New |
CWE-352
同一生成元ポリシー違反 |
CVE-2026-57305 | 2026-06-26 11:52 | 2026-06-24 | Show | GitHub Exploit DB Packet Storm |
| 184 | 6.4 |
警告
Network |
Mattermost, Inc. | Mattermost Server | Mattermost, Inc.のMattermost Serverにおけるユーザ制御の鍵による認証回避に関する脆弱性 New |
CWE-639
ユーザ制御の鍵による認証回避 |
CVE-2026-6062 | 2026-06-26 11:52 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 185 | 6.4 |
警告
Network |
Mattermost, Inc. | Mattermost Server | Mattermost, Inc.のMattermost Serverにおける重要な機能に対する認証の欠如に関する脆弱性 New |
CWE-306
重要な機能に対する認証の欠如 解説 |
CVE-2026-6673 | 2026-06-26 11:52 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 186 | 6.5 |
警告
Network |
Schneider Electric | StruxureWare Data Center Expert | Schneider Electric のStruxureWare Data Center ExpertにおけるXML 外部エンティティの脆弱性 New |
CWE-611
XML 外部エンティティ参照の不適切な制限 |
CVE-2026-8045 | 2026-06-26 11:52 | 2026-06-9 | Show | GitHub Exploit DB Packet Storm |
| 187 | 3.8 |
低
Network |
Mattermost, Inc. | Mattermost Server | Mattermost, Inc.のMattermost Serverにおける不正な認証に関する脆弱性 New |
CWE-863
不正な認証 |
CVE-2026-8074 | 2026-06-26 11:52 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 188 | 9.1 |
緊急
Network |
IBM | IBM WebSphere Application Server | IBMのIBM WebSphere Application ServerにおけるHTTP リクエストスマグリングに関する脆弱性 New |
CWE-444
HTTP リクエストスマグリング |
CVE-2026-8646 | 2026-06-26 11:52 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 189 | 8.8 |
重要
Adjacent |
IBM | IBM i | IBMのIBM Iにおけるコードインジェクションの脆弱性 New |
CWE-94
コード・インジェクション |
CVE-2026-8858 | 2026-06-26 11:51 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
| 190 | 9.1 |
緊急
Network |
IBM | IBM WebSphere Application Server | IBMのIBM WebSphere Application Serverにおけるサーバサイドのリクエストフォージェリの脆弱性 New |
CWE-918
サーバサイドリクエストフォージェリ |
CVE-2026-9006 | 2026-06-26 11:51 | 2026-06-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 27, 2026, 4:35 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 190681 | 9.8 |
CRITICAL
Network |
digi | portserver_ts_16_firmware | Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerab… |
CWE-306
Missing Authentication for Critical Function |
CVE-2021-38412 | 2024-11-21 15:17 | 2021-09-18 | Show | GitHub Exploit DB Packet Storm |
| 190682 | 7.8 |
HIGH
Local |
deltaww | dopsoft | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. … | - | CVE-2021-38406 | 2024-11-21 15:17 | 2021-09-18 | Show | GitHub Exploit DB Packet Storm |
| 190683 | 7.8 |
HIGH
Local |
deltaww | dopsoft | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacke… | - | CVE-2021-38404 | 2024-11-21 15:17 | 2021-09-18 | Show | GitHub Exploit DB Packet Storm |
| 190684 | 7.8 |
HIGH
Local |
deltaww | dopsoft | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying… | - | CVE-2021-38402 | 2024-11-21 15:17 | 2021-09-18 | Show | GitHub Exploit DB Packet Storm |
| 190685 | 7.8 |
HIGH
Local |
microsoft |
windows_server_2008 windows_10 windows_server_2016 windows_rt_8.1 windows_server_2012 windows_server_2019 windows_server_2022 windows_7 windows_8.1 |
Windows Print Spooler Elevation of Privilege Vulnerability |
CWE-269
Improper Privilege Management |
CVE-2021-38671 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |
| 190686 | 6.4 |
MEDIUM
Network |
microsoft |
edge_chromium edge |
Microsoft Edge (Chromium-based) Tampering Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-38669 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |
| 190687 | 7.8 |
HIGH
Local |
microsoft |
windows_server_2008 windows_10 windows_server_2016 windows_rt_8.1 windows_server_2012 windows_server_2019 windows_server_2022 windows_7 windows_8.1 |
Windows Print Spooler Elevation of Privilege Vulnerability |
CWE-269
Improper Privilege Management |
CVE-2021-38667 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |
| 190688 | 7.8 |
HIGH
Local |
microsoft | hevc_video_extensions | HEVC Video Extensions Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-38661 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |
| 190689 | 7.8 |
HIGH
Local |
microsoft | excel | Microsoft Office Graphics Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-38660 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |
| 190690 | 7.8 |
HIGH
Local |
microsoft | 365_apps | Microsoft Office Graphics Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-38659 | 2024-11-21 15:17 | 2021-09-15 | Show | GitHub Exploit DB Packet Storm |