Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
681 9.9 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46838 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
682 9.9 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46844 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
683 9.8 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-46845 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
684 10 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-46846 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
685 9.9 緊急
Network
オラクル Oracle WebCenter Portal オラクルのOracle WebCenter Portalにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-46847 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
686 7.9 重要
Local
オラクル Oracle WebLogic Server オラクルのOracle WebLogic Serverにおけるアクセス制御に関する脆弱性 CWE-284
CWE-noinfo
CVE-2026-46848 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
687 8.1 重要
Network
オラクル PeopleSoft Enterprise CS Campus Community オラクルのPeopleSoft Enterprise CS Campus Communityにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-46851 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
688 9.9 緊急
Network
- オラクルのEnterprise Manager Base Platformにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-46852 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
689 9.6 緊急
Network
- オラクルのEnterprise Manager Base Platformにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-46853 2026-06-22 11:53 2026-06-17 Show GitHub Exploit DB Packet Storm
690 9.9 緊急
Network
- オラクルのEnterprise Manager Base Platformにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46854 2026-06-22 11:52 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
190921 5.5 MEDIUM
Local
northern.tech cfengine The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. CWE-276
Incorrect Default Permissions 
CVE-2021-38379 2024-11-21 15:16 2021-10-28 Show GitHub Exploit DB Packet Storm
190922 7.8 HIGH
Local
nxp mcuxpresso_software_development_kit NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor(). CWE-120
Classic Buffer Overflow
CVE-2021-38260 2024-11-21 15:16 2021-10-26 Show GitHub Exploit DB Packet Storm
190923 7.8 HIGH
Local
nxp mcuxpresso_software_development_kit NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback(). CWE-120
Classic Buffer Overflow
CVE-2021-38258 2024-11-21 15:16 2021-10-26 Show GitHub Exploit DB Packet Storm
190924 9.8 CRITICAL
Network
apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus… CWE-78
OS Command 
CVE-2021-38294 2024-11-21 15:16 2021-10-25 Show GitHub Exploit DB Packet Storm
190925 9.8 CRITICAL
Network
advantech webaccess Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. CWE-787
 Out-of-bounds Write
CVE-2021-38389 2024-11-21 15:16 2021-10-18 Show GitHub Exploit DB Packet Storm
190926 9.8 CRITICAL
Network
golang
fedoraproject
go
fedora
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used. CWE-120
Classic Buffer Overflow
CVE-2021-38297 2024-11-21 15:16 2021-10-18 Show GitHub Exploit DB Packet Storm
190927 7.3 HIGH
Local
apache couchdb In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. vi… CWE-79
Cross-site Scripting
CVE-2021-38295 2024-11-21 15:16 2021-10-15 Show GitHub Exploit DB Packet Storm
190928 8.8 HIGH
Network
brizy brizy-page_builder The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The fil… CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-38346 2024-11-21 15:16 2021-10-15 Show GitHub Exploit DB Packet Storm
190929 6.5 MEDIUM
Network
brizy brizy-page_builder The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of a… CWE-863
 Incorrect Authorization
CVE-2021-38345 2024-11-21 15:16 2021-10-15 Show GitHub Exploit DB Packet Storm
190930 5.4 MEDIUM
Network
brizy brizy-page_builder The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying … - CVE-2021-38344 2024-11-21 15:16 2021-10-15 Show GitHub Exploit DB Packet Storm