Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191 5.9 警告
Network
Pivotal Software, Inc. Spring Data Commons BroadcomのSpring Data Commonsにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-41711 2026-06-17 15:37 2026-06-10 Show GitHub Exploit DB Packet Storm
192 7.5 重要
Network
Pivotal Software, Inc. Spring Data Commons BroadcomのSpring Data Commonsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41716 2026-06-17 15:37 2026-06-10 Show GitHub Exploit DB Packet Storm
193 5.9 警告
Network
Pivotal Software, Inc. Spring Data Commons BroadcomのSpring Data Commonsにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-41721 2026-06-17 15:37 2026-06-10 Show GitHub Exploit DB Packet Storm
194 7.2 重要
Local
Moby Project
Docker
Moby
moby/v2
Engine
Docker等の複数ベンダの製品における複数の脆弱性 CWE-367
CWE-61
CVE-2026-42306 2026-06-17 15:37 2026-06-12 Show GitHub Exploit DB Packet Storm
195 7.4 重要
Network
F5 Networks NGINX plus
NGINX App Protect WAF
WAF
DoS
NGINX Ingress Controller
NGINX App Protect DoS
NGINX Instance Manager
nginx o…
F5 NetworksのDoS等の複数製品における複数の脆弱性 CWE-789
CWE-823
CVE-2026-42946 2026-06-17 15:37 2026-05-13 Show GitHub Exploit DB Packet Storm
196 7.5 重要
Network
IBM Qiskit SDK IBMのQiskit SDKにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-4870 2026-06-17 15:37 2026-06-12 Show GitHub Exploit DB Packet Storm
197 5.4 警告
Network
KubeV2V Migration Planner UI KubeV2VのMigration Planner UIにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-53473 2026-06-17 15:36 2026-06-10 Show GitHub Exploit DB Packet Storm
198 6.5 警告
Network
KubeV2V Migration assessment KubeV2VのMigration assessmentにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-53474 2026-06-17 15:36 2026-06-10 Show GitHub Exploit DB Packet Storm
199 7.4 重要
Network
KubeV2V Assisted Migration Agent KubeV2VのAssisted Migration Agentにおける証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2026-53475 2026-06-17 15:36 2026-06-10 Show GitHub Exploit DB Packet Storm
200 9.6 緊急
Adjacent
KubeV2V Assisted Migration Agent KubeV2VのAssisted Migration Agentにおける複数の脆弱性 CWE-22
CWE-59
CVE-2026-53476 2026-06-17 15:36 2026-06-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
190971 9.8 CRITICAL
Network
djangoproject
fedoraproject
django
fedora
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. CWE-89
SQL Injection
CVE-2021-35042 2024-11-21 15:11 2021-07-2 Show GitHub Exploit DB Packet Storm
190972 9.8 CRITICAL
Network
zyxel usg1900_firmware
usg1100_firmware
usg310_firmware
usg210_firmware
usg110_firmware
usg40_firmware
usg40w_firmware
usg60_firmware
usg60w_firmware
usg300_firmware
usg1000_f…
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 t… CWE-287
Improper Authentication
CVE-2021-35029 2024-11-21 15:11 2021-07-2 Show GitHub Exploit DB Packet Storm
190973 8.8 HIGH
Network
istio istio Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from dif… NVD-CWE-noinfo
CVE-2021-34824 2024-11-21 15:11 2021-06-29 Show GitHub Exploit DB Packet Storm
190974 7.5 HIGH
Network
fidelissecurity deception
network
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used… CWE-522
 Insufficiently Protected Credentials
CVE-2021-35050 2024-11-21 15:11 2021-06-25 Show GitHub Exploit DB Packet Storm
190975 8.8 HIGH
Network
fidelissecurity network
deception
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute… CWE-78
OS Command 
CVE-2021-35049 2024-11-21 15:11 2021-06-25 Show GitHub Exploit DB Packet Storm
190976 9.8 CRITICAL
Network
fidelissecurity network
deception
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some v… CWE-89
SQL Injection
CVE-2021-35048 2024-11-21 15:11 2021-06-25 Show GitHub Exploit DB Packet Storm
190977 8.8 HIGH
Network
fidelissecurity network
deception
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the compon… CWE-78
OS Command 
CVE-2021-35047 2024-11-21 15:11 2021-06-25 Show GitHub Exploit DB Packet Storm
190978 7.5 HIGH
Network
fisco-bcos fisco-bcos The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format… CWE-20
 Improper Input Validation 
CVE-2021-35041 2024-11-21 15:11 2021-06-24 Show GitHub Exploit DB Packet Storm
190979 6.1 MEDIUM
Network
icehrm icehrm A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie. CWE-384
 Session Fixation
CVE-2021-35046 2024-11-21 15:11 2021-06-22 Show GitHub Exploit DB Packet Storm
190980 6.1 MEDIUM
Network
icehrm icehrm Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint. CWE-79
Cross-site Scripting
CVE-2021-35045 2024-11-21 15:11 2021-06-22 Show GitHub Exploit DB Packet Storm