Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
261 7.5 重要
Network
AIOHTTP AIOHTTP AIOHTTPにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-54274 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
262 7.5 重要
Network
AIOHTTP AIOHTTP AIOHTTPにおけるホストの不一致による証明書の検証に関する脆弱性 New CWE-297
ホストの不一致による証明書の不適切な検証
CVE-2026-54275 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
263 7.5 重要
Network
AIOHTTP AIOHTTP AIOHTTPにおける高圧縮データの処理 (データ増幅)に関する脆弱性 New CWE-409
高圧縮データの不適切な処理 (データ増幅)
CVE-2026-54278 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
264 7.5 重要
Network
AIOHTTP AIOHTTP AIOHTTPにおける初期化に関する脆弱性 New CWE-665
不適切な初期化
CVE-2026-54279 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
265 7.5 重要
Network
AIOHTTP AIOHTTP AIOHTTPにおけるリソースの不適切なシャットダウンおよびリリースに関する脆弱性 New CWE-404
リソースの不適切なシャットダウンおよびリリース
CVE-2026-54280 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
266 5.3 警告
Network
Encode Starlette EncodeのStarletteにおける誤って解決された名前や参照の使用に関する脆弱性 New CWE-706
誤って解決された名前や参照の使用
CVE-2026-54282 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
267 7.5 重要
Network
Encode Starlette EncodeのStarletteにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 New CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-54283 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
268 7.5 重要
Network
NLTK NLTK NLTKにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-54293 2026-06-29 11:12 2026-06-22 Show GitHub Exploit DB Packet Storm
269 7.5 重要
Network
Faraday Project Faraday Faraday ProjectのFaradayにおける再帰制御に関する脆弱性 New CWE-674
不適切な再帰制御
CVE-2026-54297 2026-06-29 11:12 2026-06-24 Show GitHub Exploit DB Packet Storm
270 5.4 警告
Network
n8n n8n n8nにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-54301 2026-06-29 11:12 2026-06-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320851 - - - VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assi… - CVE-2024-38818 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320852 - - - VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive infor… - CVE-2024-38815 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320853 - - - HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request d… - CVE-2024-30118 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320854 - - - ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki h… CWE-282
 Improper Ownership Management
CVE-2024-47816 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320855 - - - IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permis… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2024-47815 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320856 - - - A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. - CVE-2024-9470 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320857 - - - A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of ser… - CVE-2024-9468 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320858 7.4 HIGH
Network
- - Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector CWE-200
Information Exposure
CVE-2024-43610 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320859 - - - ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS p… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2024-47812 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320860 - - - Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-47813 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm