Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3371 7.1 重要
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-3473 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
3372 6.7 警告
Local
デル smartfabric storage software デルのsmartfabric storage softwareにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-35070 2026-05-28 14:42 2026-05-20 Show GitHub Exploit DB Packet Storm
3373 4.3 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-3636 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
3374 6.5 警告
Network
The Go Project crypto The Go Projectのcryptoにおける通信チャネルで送信中のメッセージの整合性への不適切な強制に関する脆弱性 CWE-924
通信チャネルで送信中のメッセージの整合性への不適切な強制
CVE-2026-39827 2026-05-28 14:42 2026-05-22 Show GitHub Exploit DB Packet Storm
3375 3.3
Local
Artifex Software MuPDF Artifex SoftwareのMuPDFにおけるエスケープ、メタ、またはコントロールシーケンスの不適切な無効化に関する脆弱性 CWE-150
エスケープ、メタ、またはコントロールシーケンスの不適切な無効化
CVE-2026-40505 2026-05-28 14:42 2026-04-16 Show GitHub Exploit DB Packet Storm
3376 7.5 重要
Network
NLnet Labs unbound NLnet Labsのunboundにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-40622 2026-05-28 14:42 2026-05-20 Show GitHub Exploit DB Packet Storm
3377 4.8 警告
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-41999 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
3378 8.6 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-42000 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
3379 7.5 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-42001 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
3380 7.5 重要
Network
PowerDNS PowerDNS Authoritative Server PowerDNSのPowerDNS Authoritative Serverにおけるシグナルハンドラの競合状態に関する脆弱性 CWE-364
シグナルハンドラの競合状態
CVE-2026-42002 2026-05-28 14:42 2026-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319471 8.8 HIGH
Network
buffercode frontend_dashboard The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up… CWE-94
Code Injection
CVE-2024-8268 2024-09-27 01:15 2024-09-10 Show GitHub Exploit DB Packet Storm
319472 6.5 MEDIUM
Network
pinpoint pinpoint_booking_system The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insuf… CWE-89
SQL Injection
CVE-2024-7112 2024-09-27 01:12 2024-09-7 Show GitHub Exploit DB Packet Storm
319473 7.3 HIGH
Network
ifeelweb affiliate_super_assistent The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply… CWE-94
Code Injection
CVE-2024-8478 2024-09-27 00:53 2024-09-10 Show GitHub Exploit DB Packet Storm
319474 5.3 MEDIUM
Network
metagauss eventprime The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all ver… CWE-862
 Missing Authorization
CVE-2024-8369 2024-09-27 00:43 2024-09-10 Show GitHub Exploit DB Packet Storm
319475 8.8 HIGH
Network
elizsoftware panel Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel:… CWE-89
SQL Injection
CVE-2024-5958 2024-09-27 00:35 2024-09-19 Show GitHub Exploit DB Packet Storm
319476 6.5 MEDIUM
Network
apexsoftcell ld_geo
ld_dp_back_office
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacke… NVD-CWE-Other
CVE-2024-47085 2024-09-27 00:30 2024-09-19 Show GitHub Exploit DB Packet Storm
319477 5.4 MEDIUM
Network
code-projects blood_bank_system A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file bbms.php. The manipulation of the argument fullname/age… CWE-79
Cross-site Scripting
CVE-2024-9084 2024-09-27 00:29 2024-09-22 Show GitHub Exploit DB Packet Storm
319478 6.5 MEDIUM
Network
apexsoftcell ld_geo
ld_dp_back_office
This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this v… NVD-CWE-Other
CVE-2024-47086 2024-09-27 00:29 2024-09-19 Show GitHub Exploit DB Packet Storm
319479 9.8 CRITICAL
Network
code-projects restaurant_reservation_system A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument fro… CWE-89
SQL Injection
CVE-2024-9086 2024-09-27 00:26 2024-09-23 Show GitHub Exploit DB Packet Storm
319480 6.5 MEDIUM
Network
apexsoftcell ld_geo
ld_dp_back_office
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit th… NVD-CWE-Other
CVE-2024-47087 2024-09-27 00:25 2024-09-19 Show GitHub Exploit DB Packet Storm