Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248041 7.5 危険 Exiv2 project - exiv2 library の exif.cpp における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2007-6353 2012-06-26 15:54 2007-12-19 Show GitHub Exploit DB Packet Storm
248042 7.5 危険 aurora - aurora framework における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6345 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
248043 7.5 危険 david castro - Apache HTTP Server の David Castro AuthCAS.pm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6342 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
248044 7.5 危険 avs media - Online Media Technologies AVSMJPEGFILE.DLL の特定の ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6327 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
248045 6.8 警告 fastpublish - Fastpublish CMS の adminbereich/designconfig.php における PHP リモートファイルインクルージョンの脆弱性 CWE-20
CWE-94
CVE-2007-6325 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
248046 6.8 警告 city writer - CityWriter の head.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6324 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
248047 4.3 警告 Drupal - Drupal の Feature モジュールにおけるクロスサイトリクエストフォージェリ攻撃を誘発する脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6320 2012-06-26 15:54 2007-12-5 Show GitHub Exploit DB Packet Storm
248048 7.5 危険 falt4 cms - Falt4Extreme RC4 の index.php および admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6311 2012-06-26 15:54 2007-12-11 Show GitHub Exploit DB Packet Storm
248049 4.3 警告 falt4 cms - Falt4Extreme RC4 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6310 2012-06-26 15:54 2007-12-11 Show GitHub Exploit DB Packet Storm
248050 5 警告 fusion news - Fusion News におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6300 2012-06-26 15:54 2007-12-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199441 7.8 HIGH
Local
codesys development_system A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially cra… CWE-502
 Deserialization of Untrusted Data
CVE-2021-21864 2024-11-21 14:49 2021-08-3 Show GitHub Exploit DB Packet Storm
199442 6.5 MEDIUM
Network
elastic
oracle
elasticsearch
communications_cloud_native_core_automated_test_suite
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with t… CWE-674
 Uncontrolled Recursion
CVE-2021-22144 2024-11-21 14:49 2021-07-26 Show GitHub Exploit DB Packet Storm
199443 7.5 HIGH
Network
cloudfoundry user_account_and_authentication
cf-deployment
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent t… NVD-CWE-noinfo
CVE-2021-22001 2024-11-21 14:49 2021-07-22 Show GitHub Exploit DB Packet Storm
199444 7.5 HIGH
Network
elastic elasticsearch All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unab… NVD-CWE-Other
CVE-2021-22146 2024-11-21 14:49 2021-07-22 Show GitHub Exploit DB Packet Storm
199445 6.5 MEDIUM
Network
elastic
oracle
elasticsearch
communications_cloud_native_core_automated_test_suite
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query… CWE-209
Information Exposure Through an Error Message
CVE-2021-22145 2024-11-21 14:49 2021-07-22 Show GitHub Exploit DB Packet Storm
199446 7.5 HIGH
Network
wireshark
debian
wireshark
debian_linux
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-22235 2024-11-21 14:49 2021-07-20 Show GitHub Exploit DB Packet Storm
199447 7.2 HIGH
Network
fortinet fortisandbox An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's s… CWE-78
OS Command 
CVE-2021-22125 2024-11-21 14:49 2021-07-20 Show GitHub Exploit DB Packet Storm
199448 9.8 CRITICAL
Network
dlink dir-3040_firmware A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can sen… CWE-798
 Use of Hard-coded Credentials
CVE-2021-21820 2024-11-21 14:49 2021-07-16 Show GitHub Exploit DB Packet Storm
199449 7.2 HIGH
Network
dlink dir-3040_firmware A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker… CWE-78
OS Command 
CVE-2021-21819 2024-11-21 14:49 2021-07-16 Show GitHub Exploit DB Packet Storm
199450 7.5 HIGH
Network
dlink dir-3040_firmware A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker c… CWE-798
 Use of Hard-coded Credentials
CVE-2021-21818 2024-11-21 14:49 2021-07-16 Show GitHub Exploit DB Packet Storm