Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131 9.9 緊急
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2026-54310 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
132 7.7 重要
Network
n8n n8n n8nにおける誤ったセッションへのデータ要素の漏えいに関する脆弱性 New CWE-488
誤ったセッションへのデータ要素の漏えい
CVE-2026-54311 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
133 8.5 重要
Network
n8n n8n n8nにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 New CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-54312 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
134 7.7 重要
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2026-54313 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
135 7.5 重要
Network
n8n n8n n8nにおける高圧縮データの処理 (データ増幅)に関する脆弱性 New CWE-409
高圧縮データの不適切な処理 (データ増幅)
CVE-2026-54314 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
136 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおける無限ループに関する脆弱性 New CWE-835
無限ループ
CVE-2026-54530 2026-06-26 11:54 2026-06-22 Show GitHub Exploit DB Packet Storm
137 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおける無限ループに関する脆弱性 New CWE-835
無限ループ
CVE-2026-54531 2026-06-26 11:54 2026-06-22 Show GitHub Exploit DB Packet Storm
138 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおける無限ループに関する脆弱性 New CWE-835
無限ループ
CVE-2026-54651 2026-06-26 11:54 2026-06-22 Show GitHub Exploit DB Packet Storm
139 5.3 警告
Network
Apache Software Foundation Apache NiFi Apache Software FoundationのApache NiFiにおける同一生成元ポリシー違反に関する脆弱性 New CWE-346
同一生成元ポリシー違反
CVE-2026-54665 2026-06-26 11:54 2026-06-22 Show GitHub Exploit DB Packet Storm
140 9.9 緊急
Network
langflow langflow langflowにおけるユーザ制御の鍵による認証回避に関する脆弱性 New CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-55255 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320811 7.2 HIGH
Network
lifterlms lifterlms The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to … CWE-89
SQL Injection
CVE-2024-7349 2024-09-12 21:43 2024-09-6 Show GitHub Exploit DB Packet Storm
320812 9.8 CRITICAL
Network
plechevandrey wp-recall The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plu… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-8292 2024-09-12 21:37 2024-09-6 Show GitHub Exploit DB Packet Storm
320813 - - - A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDat… CWE-89
SQL Injection
CVE-2024-8705 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320814 - - - A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.ad… CWE-22
Path Traversal
CVE-2024-8694 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320815 - - - A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipula… CWE-79
Cross-site Scripting
CVE-2024-8693 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320816 - - - evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin." - CVE-2024-44541 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320817 - - - A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. - CVE-2024-8689 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320818 - - - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This is… - CVE-2024-8097 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320819 - - - RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. - CVE-2024-44577 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm
320820 - - - RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. - CVE-2024-44574 2024-09-12 21:35 2024-09-12 Show GitHub Exploit DB Packet Storm