Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
21 8.8 重要
Network
Stichting NLnet Labs NSD NLnet LabsのNSDにおける複数の脆弱性 New CWE-122
CWE-190
CVE-2026-12244 2026-06-29 11:25 2026-06-25 Show GitHub Exploit DB Packet Storm
22 7.5 重要
Network
Stichting NLnet Labs NSD NLnet LabsのNSDにおける解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-12245 2026-06-29 11:25 2026-06-25 Show GitHub Exploit DB Packet Storm
23 8.1 重要
Network
Stichting NLnet Labs NSD NLnet LabsのNSDにおける複数の脆弱性 New CWE-120
CWE-20
CVE-2026-12246 2026-06-29 11:25 2026-06-25 Show GitHub Exploit DB Packet Storm
24 6.1 警告
Network
PowerSchool Inc. Employee Access Center PowerSchool Inc.のEmployee Access Centerにおけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-12425 2026-06-29 11:25 2026-06-16 Show GitHub Exploit DB Packet Storm
25 7.5 重要
Network
Stichting NLnet Labs NSD NLnet LabsのNSDにおける複数の脆弱性 New CWE-284
CWE-306
CVE-2026-12490 2026-06-29 11:25 2026-06-25 Show GitHub Exploit DB Packet Storm
26 7.1 重要
Local
シーメンス SIMATIC WinCC Unified PC Runtime シーメンスのSIMATIC WinCC Unified PC Runtimeにおけるファイル内またはディスク上の平文保存に関する脆弱性 New CWE-313
ファイル内またはディスク上の平文保存
CVE-2026-24349 2026-06-29 11:25 2026-06-9 Show GitHub Exploit DB Packet Storm
27 8.2 重要
Network
Docling Docling Doclingにおける複数の脆弱性 New CWE-918
CWE-94
CVE-2026-44016 2026-06-29 11:25 2026-06-24 Show GitHub Exploit DB Packet Storm
28 7.5 重要
Network
Docling Docling Doclingにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-44017 2026-06-29 11:25 2026-06-24 Show GitHub Exploit DB Packet Storm
29 7.5 重要
Network
Docling Docling DoclingにおけるDTD の再帰的なエンティティ参照の不適切な制限に関する脆弱性 New CWE-776
DTD の再帰的なエンティティ参照の不適切な制限
CVE-2026-44020 2026-06-29 11:25 2026-06-24 Show GitHub Exploit DB Packet Storm
30 5.5 警告
Local
Docling Docling Doclingにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-44022 2026-06-29 11:25 2026-06-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320761 6.1 MEDIUM
Network
yoginetwork rabbitloader The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… CWE-79
Cross-site Scripting
CVE-2024-8800 2024-10-9 03:59 2024-10-2 Show GitHub Exploit DB Packet Storm
320762 6.1 MEDIUM
Network
themes4wp popularis_extra The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up … CWE-79
Cross-site Scripting
CVE-2024-9353 2024-10-9 03:50 2024-10-4 Show GitHub Exploit DB Packet Storm
320763 5.4 MEDIUM
Network
iworks pwa The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input … CWE-79
Cross-site Scripting
CVE-2024-8967 2024-10-9 03:47 2024-10-2 Show GitHub Exploit DB Packet Storm
320764 7.5 HIGH
Network
cisco meraki_mx65_firmware
meraki_mx64_firmware
meraki_z4c_firmware
meraki_z4_firmware
meraki_z3c_firmware
meraki_z3_firmware
meraki_vmx_firmware
meraki_mx600_firmware
meraki_mx450_…
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on … CWE-400
 Uncontrolled Resource Consumption
CVE-2024-20502 2024-10-9 03:46 2024-10-3 Show GitHub Exploit DB Packet Storm
320765 6.5 MEDIUM
Network
soplanning soplanning SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to… CWE-89
SQL Injection
CVE-2024-9574 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
320766 6.5 MEDIUM
Network
soplanning soplanning SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the in… CWE-89
SQL Injection
CVE-2024-9573 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
320767 5.4 MEDIUM
Network
soplanning soplanning Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow … CWE-79
Cross-site Scripting
CVE-2024-9572 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
320768 5.4 MEDIUM
Network
soplanning soplanning Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could al… CWE-79
Cross-site Scripting
CVE-2024-9571 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
320769 5.9 MEDIUM
Network
cisco meraki_mx65_firmware
meraki_mx64_firmware
meraki_z4c_firmware
meraki_z4_firmware
meraki_z3c_firmware
meraki_z3_firmware
meraki_vmx_firmware
meraki_mx600_firmware
meraki_mx450_…
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN … CWE-362
Race Condition
CVE-2024-20509 2024-10-9 03:45 2024-10-3 Show GitHub Exploit DB Packet Storm
320770 8.8 HIGH
Network
dlink dir-605l_firmware A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The mani… CWE-120
Classic Buffer Overflow
CVE-2024-9565 2024-10-9 03:39 2024-10-7 Show GitHub Exploit DB Packet Storm