Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247861 4.3 警告 gadu-gadu - Gadu-Gadu におけるクロスサイトリクエストフォージェリ攻撃の脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6410 2012-06-26 15:54 2007-12-17 Show GitHub Exploit DB Packet Storm
247862 4.3 警告 gadu-gadu - Gadu-Gadu の gg プロトコルハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2007-6409 2012-06-26 15:54 2007-12-17 Show GitHub Exploit DB Packet Storm
247863 4.3 警告 CA Technologies - CA eTrust Threat Management Console におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6406 2012-06-26 15:54 2007-12-17 Show GitHub Exploit DB Packet Storm
247864 6.5 警告 ace image hosting script - Ace Image Hosting Script の albums.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6393 2012-06-26 15:54 2007-12-17 Show GitHub Exploit DB Packet Storm
247865 7.5 危険 dominion web - DWdirectory における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6392 2012-06-26 15:54 2007-12-17 Show GitHub Exploit DB Packet Storm
247866 2.1 注意 GNOME Project - GNOME screensaver の通知機能におけるクリップボードの内容などを読まれる脆弱性 CWE-DesignError
CVE-2007-6389 2012-06-26 15:54 2007-12-11 Show GitHub Exploit DB Packet Storm
247867 7.5 危険 BEAシステムズ - BEA WebLogic Mobility Server の Image Converter 機能におけるアプリケーションファイルおよびリソースアクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2007-6384 2012-06-26 15:54 2007-12-14 Show GitHub Exploit DB Packet Storm
247868 5.5 警告 chandler project - Cosmo のDAV コンポーネントにおける他ユーザのホームコレクションの任意のリソースを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6383 2012-06-26 15:54 2007-12-14 Show GitHub Exploit DB Packet Storm
247869 7.5 危険 e-xoops - exoops における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6380 2012-06-26 15:54 2007-12-14 Show GitHub Exploit DB Packet Storm
247870 5 警告 badblue - BadBlue における重要な情報を取得される脆弱性 CWE-16
環境設定
CVE-2007-6379 2012-06-26 15:54 2007-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199611 5.0 MEDIUM
Network
gitlab gitlab An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2021-22178 2024-11-21 14:49 2021-03-25 Show GitHub Exploit DB Packet Storm
199612 4.3 MEDIUM
Network
gitlab gitlab An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests CWE-863
 Incorrect Authorization
CVE-2021-22176 2024-11-21 14:49 2021-03-25 Show GitHub Exploit DB Packet Storm
199613 7.8 HIGH
Local
huawei manageone There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitat… NVD-CWE-noinfo
CVE-2021-22314 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199614 7.2 HIGH
Network
huawei manageone There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow c… CWE-276
Incorrect Default Permissions 
CVE-2021-22311 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199615 5.3 MEDIUM
Network
huawei nip6300_firmware
nip6600_firmware
nip6800_firmware
s12700_firmware
s1700_firmware
s2700_firmware
s5700_firmware
s6700_firmware
s7700_firmware
s9700_firmware
secospace_us…
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious opera… CWE-416
 Use After Free
CVE-2021-22321 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199616 7.5 HIGH
Network
huawei ips_module_firmware
ngfw_module_firmware
nip6600_firmware
nip6800_firmware
secospace_usg6300_firmware
secospace_usg6500_firmware
secospace_usg6600_firmware
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affe… NVD-CWE-noinfo
CVE-2021-22320 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199617 4.4 MEDIUM
Local
huawei nip6300_firmware
nip6600_firmware
secospace_usg6300_firmware
secospace_usg6500_firmware
secospace_usg6600_firmware
usg9500_firmware
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2021-22310 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199618 7.5 HIGH
Network
huawei usg9500_firmware
usg9520_firmware
usg9560_firmware
usg9580_firmware
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive mess… CWE-330
 Use of Insufficiently Random Values
CVE-2021-22309 2024-11-21 14:49 2021-03-23 Show GitHub Exploit DB Packet Storm
199619 8.8 HIGH
Network
wireshark
oracle
debian
wireshark
zfs_storage_appliance
debian_linux
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. CWE-74
Injection
CVE-2021-22191 2024-11-21 14:49 2021-03-16 Show GitHub Exploit DB Packet Storm
199620 4.3 MEDIUM
Network
elastic
oracle
elasticsearch
communications_cloud_native_core_automated_test_suite
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions whe… CWE-863
 Incorrect Authorization
CVE-2021-22134 2024-11-21 14:49 2021-03-9 Show GitHub Exploit DB Packet Storm