Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3221 9.6 緊急
Network
charm Wish charmのWishにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41589 2026-06-3 17:04 2026-05-7 Show GitHub Exploit DB Packet Storm
3222 9.1 緊急
Network
i18next i18next-http-backend i18nextのi18next-http-backendにおける複数の脆弱性 CWE-22
CWE-74
CVE-2026-41691 2026-06-3 17:04 2026-05-7 Show GitHub Exploit DB Packet Storm
3223 4.7 警告
Network
i18next i18nextify i18nextのi18nextifyにおける複数の脆弱性 CWE-79
CWE-94
CVE-2026-41692 2026-06-3 17:04 2026-05-7 Show GitHub Exploit DB Packet Storm
3224 10 緊急
Network
th30d4y OpenLearnX th30d4yのOpenLearnXにおける複数の脆弱性 CWE-250
CWE-284
CWE-693
CWE-78
CWE-94
CVE-2026-41900 2026-06-3 17:04 2026-05-8 Show GitHub Exploit DB Packet Storm
3225 6.1 警告
Network
The Go Project Net The Go ProjectのNetにおけるレンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限に関する脆弱性 CWE-1021
レンダリングされたユーザインターフェースレイヤまたはフレームの不適切な制限
CVE-2026-42502 2026-06-3 17:04 2026-05-22 Show GitHub Exploit DB Packet Storm
3226 6.1 警告
Network
The Go Project Net The Go ProjectのNetにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42506 2026-06-3 17:04 2026-05-22 Show GitHub Exploit DB Packet Storm
3227 7.8 重要
Local
horsicq Detect-It-Easy horsicqのDetect-It-Easyにおける相対パストラバーサルの脆弱性 CWE-23
相対的パストラバーサル
CVE-2026-43616 2026-06-3 17:04 2026-05-4 Show GitHub Exploit DB Packet Storm
3228 9.9 緊急
Network
オラクル Oracle iAssets オラクルのOracle iAssetsにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-46822 2026-06-3 17:04 2026-05-28 Show GitHub Exploit DB Packet Storm
3229 7.5 重要
Network
fastify fastify/accepts-serializer fastifyのfastify/accepts-serializerにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-7768 2026-06-3 17:04 2026-05-4 Show GitHub Exploit DB Packet Storm
3230 8.8 重要
Local
NanoCo NanoClaw NanoCoのNanoClawにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-7875 2026-06-3 17:04 2026-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319831 4.3 MEDIUM
Network
splunk splunk
splunk_cloud_platform
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold th… NVD-CWE-noinfo
CVE-2024-45735 2024-10-17 07:20 2024-10-15 Show GitHub Exploit DB Packet Storm
319832 4.3 MEDIUM
Network
splunk splunk In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by usi… NVD-CWE-noinfo
CVE-2024-45734 2024-10-17 07:20 2024-10-15 Show GitHub Exploit DB Packet Storm
319833 6.5 MEDIUM
Network
splunk splunk
splunk_cloud_platform
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin"… NVD-CWE-noinfo
CVE-2024-45736 2024-10-17 07:19 2024-10-15 Show GitHub Exploit DB Packet Storm
319834 3.5 LOW
Network
splunk splunk
splunk_cloud_platform
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Sp… CWE-352
 Origin Validation Error
CVE-2024-45737 2024-10-17 07:18 2024-10-15 Show GitHub Exploit DB Packet Storm
319835 7.5 HIGH
Network
- - An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically … CWE-125
Out-of-bounds Read
CVE-2024-39516 2024-10-17 07:15 2024-10-10 Show GitHub Exploit DB Packet Storm
319836 8.8 HIGH
Network
blood_bank_system_project blood_bank_system A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The manipulation of the argument useremail … CWE-89
SQL Injection
CVE-2024-9894 2024-10-17 07:13 2024-10-12 Show GitHub Exploit DB Packet Storm
319837 5.4 MEDIUM
Network
oretnom23 online_eyewear_shop A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The … CWE-79
Cross-site Scripting
CVE-2024-9906 2024-10-17 07:12 2024-10-13 Show GitHub Exploit DB Packet Storm
319838 8.8 HIGH
Network
oretnom23 online_eyewear_shop A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /admin/?page=inventory/view_invento… CWE-89
SQL Injection
CVE-2024-9905 2024-10-17 07:12 2024-10-13 Show GitHub Exploit DB Packet Storm
319839 9.8 CRITICAL
Network
usualtool usualtoolcms A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipula… CWE-78
OS Command 
CVE-2024-9916 2024-10-17 07:11 2024-10-14 Show GitHub Exploit DB Packet Storm
319840 9.8 CRITICAL
Network
ragic enterprise_cloud_database Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie. CWE-306
Missing Authentication for Critical Function
CVE-2024-9984 2024-10-17 07:03 2024-10-15 Show GitHub Exploit DB Packet Storm