Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
651 10 緊急
Network
UI UniFi Dream Machine Special Edition Firmware (UDM-SE)
UniFi Cloud Gateway Ultra Firmware (UCG-Ultra)
UniFi Network Video Re…
UIのEnterprise Fortress Gateway Firmware (EFG)等の複数製品における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-34910 2026-06-26 11:49 2026-05-22 Show GitHub Exploit DB Packet Storm
652 9.1 緊急
Network
vLLM vLLM vLLMにおけるHTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2026-48746 2026-06-26 11:49 2026-06-22 Show GitHub Exploit DB Packet Storm
653 6.7 警告
Local
デル Dell Peripheral Manager デルのDell Peripheral Managerにおける制御されていない検索パスの要素に関する脆弱性 CWE-427
制御されていない検索パスの要素
CVE-2024-22451 2026-06-26 11:49 2026-06-16 Show GitHub Exploit DB Packet Storm
654 8.8 重要
Network
HarfBuzz project HarfBuzz HarfBuzz projectのHarfBuzzにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2024-56732 2026-06-26 11:49 2024-12-27 Show GitHub Exploit DB Packet Storm
655 5.4 警告
Network
Apache Software Foundation Apache Atlas Apache Software FoundationのApache Atlasにおけるクロスサイトスクリプティングの脆弱性 CWE-80
クロスサイトスクリプティング (Basic XSS)
CVE-2025-62198 2026-06-26 11:49 2026-06-22 Show GitHub Exploit DB Packet Storm
656 4.7 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2025-71303 2026-06-26 11:49 2026-05-27 Show GitHub Exploit DB Packet Storm
657 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71304 2026-06-26 11:49 2026-05-27 Show GitHub Exploit DB Packet Storm
658 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-71305 2026-06-26 11:49 2026-05-27 Show GitHub Exploit DB Packet Storm
659 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2025-71306 2026-06-26 11:49 2026-05-27 Show GitHub Exploit DB Packet Storm
660 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2025-71307 2026-06-26 11:49 2026-05-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
190781 6.3 MEDIUM
Local
bytecodealliance
fedoraproject
wasmtime
fedora
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 there was a use-after-free bug when passing `externref`s from the host to guest Wa… - CVE-2021-39216 2024-11-21 15:18 2021-09-18 Show GitHub Exploit DB Packet Storm
190782 9.8 CRITICAL
Network
linuxfoundation tremor Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `sta… CWE-416
 Use After Free
CVE-2021-39228 2024-11-21 15:18 2021-09-17 Show GitHub Exploit DB Packet Storm
190783 9.8 CRITICAL
Network
baidu zrender ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototy… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-39227 2024-11-21 15:18 2021-09-17 Show GitHub Exploit DB Packet Storm
190784 7.5 HIGH
Network
apache jena A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote ser… CWE-611
XXE
CVE-2021-39239 2024-11-21 15:18 2021-09-17 Show GitHub Exploit DB Packet Storm
190785 9.8 CRITICAL
Network
mitmproxy mitmproxy mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This m… - CVE-2021-39214 2024-11-21 15:18 2021-09-17 Show GitHub Exploit DB Packet Storm
190786 4.3 MEDIUM
Network
sharpcompress_project sharpcompress SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 are vulnerable to partial path traversal. SharpCompress recreates a hierarchy of … - CVE-2021-39208 2024-11-21 15:18 2021-09-17 Show GitHub Exploit DB Packet Storm
190787 7.2 HIGH
Network
atlassian jira_server
jira_data_center
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-si… CWE-94
Code Injection
CVE-2021-39128 2024-11-21 15:18 2021-09-16 Show GitHub Exploit DB Packet Storm
190788 7.5 HIGH
Network
8x8 jitsi_meet Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that toke… - CVE-2021-39215 2024-11-21 15:18 2021-09-16 Show GitHub Exploit DB Packet Storm
190789 6.1 MEDIUM
Network
8x8 jitsi_meet Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not pro… CWE-79
CWE-1321
Cross-site Scripting
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-39205 2024-11-21 15:18 2021-09-16 Show GitHub Exploit DB Packet Storm
190790 8.8 HIGH
Network
glpi-project glpi GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This … CWE-74
Injection
CVE-2021-39213 2024-11-21 15:18 2021-09-16 Show GitHub Exploit DB Packet Storm