|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 27, 2026, 2 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 601 | 6.3 |
警告
Network |
シスコシステムズ | Cisco Crosswork Network Controller | シスコシステムズのCisco Crosswork Network Controllerにおけるインジェクションに関する脆弱性 |
CWE-74
インジェクション |
CVE-2026-20220 | 2026-06-23 10:01 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 602 | 4.3 |
警告
Network |
Splunk | Splunk AI Toolkit | SplunkのSplunk AI Toolkitにおけるリソースの安全ではないデフォルト値への初期化に関する脆弱性 |
CWE-1188
リソースの安全ではないデフォルト値への初期化 |
CVE-2026-20265 | 2026-06-23 10:00 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 603 | 9.1 |
緊急
Network |
Splunk | Splunk AI Toolkit | SplunkのSplunk AI ToolkitにおけるOS コマンドインジェクションの脆弱性 |
CWE-78
OSコマンド・インジェクション |
CVE-2026-20266 | 2026-06-23 10:00 | 2026-06-17 | Show | GitHub Exploit DB Packet Storm |
| 604 | 5.9 |
警告
Network |
VMware | Spring Data MongoDB | VMwareのSpring Data MongoDBにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 |
CWE-943
データクエリロジックの特殊要素の不適切な中立化 |
CVE-2026-41696 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 605 | 8.1 |
重要
Network |
VMware | Spring Data MongoDB | VMwareのSpring Data MongoDBにおける言語構文の表現に使用される特殊な要素の不適切な無効化に関する脆弱性 |
CWE-917
言語構文の表現に使用される特殊な要素の不適切な無効化 |
CVE-2026-41717 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 606 | 6.5 |
警告
Network |
VMware | spring for apache kafka | VMwareのspring for apache kafkaにおける入力確認に関する脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2026-41727 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 607 | 7.5 |
重要
Network |
VMware | Spring Data REST | VMwareのSpring Data RESTにおけるアクセス制御に関する脆弱性 |
CWE-284
不適切なアクセス制御 |
CVE-2026-41728 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 608 | 8.1 |
重要
Network |
VMware | Spring Data REST | VMwareのSpring Data RESTにおける言語構文の表現に使用される特殊な要素の不適切な無効化に関する脆弱性 |
CWE-917
言語構文の表現に使用される特殊な要素の不適切な無効化 |
CVE-2026-41729 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 609 | 5.3 |
警告
Network |
VMware | Spring Data REST | VMwareのSpring Data RESTにおけるエラーメッセージによる情報漏えいに関する脆弱性 |
CWE-209
エラーメッセージによる情報漏えい |
CVE-2026-41730 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
| 610 | 8.1 |
重要
Network |
VMware | spring for apache kafka | VMwareのspring for apache kafkaにおける信頼できないデータのデシリアライゼーションに関する脆弱性 |
CWE-502
信頼性のないデータのデシリアライゼーション |
CVE-2026-41731 | 2026-06-23 10:00 | 2026-06-10 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 27, 2026, 4:35 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 191241 | 9.8 |
CRITICAL
Network |
zohocorp | manageengine_admanager_plus | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-37761 | 2024-11-21 15:15 | 2021-09-28 | Show | GitHub Exploit DB Packet Storm |
| 191242 | 9.8 |
CRITICAL
Network |
zohocorp | manageengine_admanager_plus | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-37539 | 2024-11-21 15:15 | 2021-09-28 | Show | GitHub Exploit DB Packet Storm |
| 191243 | 4.6 |
MEDIUM
Physics |
bag | covid_certificate | Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0… |
CWE-755
Improper Handling of Exceptional Conditions |
CVE-2021-37786 | 2024-11-21 15:15 | 2021-09-27 | Show | GitHub Exploit DB Packet Storm |
| 191244 | 6.1 |
MEDIUM
Network |
mattermost | mattermost | Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the … |
CWE-79
Cross-site Scripting |
CVE-2021-37860 | 2024-11-21 15:15 | 2021-09-23 | Show | GitHub Exploit DB Packet Storm |
| 191245 | 8.8 |
HIGH
Network |
zohocorp | manageengine_admanager_plus | ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-37741 | 2024-11-21 15:15 | 2021-09-21 | Show | GitHub Exploit DB Packet Storm |
| 191246 | 9.8 |
CRITICAL
Network |
zohocorp | manageengine_admanager_plus | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. |
NVD-CWE-noinfo
|
CVE-2021-37424 | 2024-11-21 15:15 | 2021-09-21 | Show | GitHub Exploit DB Packet Storm |
| 191247 | 6.5 |
MEDIUM
Network |
zohocorp | manageengine_admanager_plus | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. |
CWE-306
Missing Authentication for Critical Function |
CVE-2021-37420 | 2024-11-21 15:15 | 2021-09-21 | Show | GitHub Exploit DB Packet Storm |
| 191248 | 7.5 |
HIGH
Network |
zohocorp | manageengine_admanager_plus | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2021-37419 | 2024-11-21 15:15 | 2021-09-21 | Show | GitHub Exploit DB Packet Storm |
| 191249 | 6.1 |
MEDIUM
Network |
it-economics | techradar | The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar. |
CWE-79
Cross-site Scripting |
CVE-2021-37412 | 2024-11-21 15:15 | 2021-09-16 | Show | GitHub Exploit DB Packet Storm |
| 191250 | 9.8 |
CRITICAL
Network |
sap | netweaver_application_server_java | SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges. |
CWE-862
Missing Authorization |
CVE-2021-37535 | 2024-11-21 15:15 | 2021-09-14 | Show | GitHub Exploit DB Packet Storm |