Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
511 7.5 重要
Network
MessagePack MessagePack MessagePackにおける再帰制御に関する脆弱性 CWE-674
不適切な再帰制御
CVE-2026-48513 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
512 7.5 重要
Network
MessagePack MessagePack MessagePackにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-48514 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
513 7.5 重要
Network
MessagePack MessagePack MessagePackにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-48515 2026-06-26 11:57 2026-06-22 Show GitHub Exploit DB Packet Storm
514 7.5 重要
Network
MessagePack MessagePack MessagePackにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-48516 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
515 7.5 重要
Network
MessagePack MessagePack MessagePackにおける複数の脆弱性 CWE-470
CWE-502
CVE-2026-48517 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
516 9.6 緊急
Network
マイクロソフト Microsoft Exchange Online Microsoft Exchange Online Elevation of Privilege Vulnerability CWE-862
認証の欠如
CVE-2026-48582 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
517 7.2 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-48895 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
518 5.3 警告
Network
markdown-it project markdown-it markdown-it projectのmarkdown-itにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-48988 2026-06-26 11:56 2026-06-17 Show GitHub Exploit DB Packet Storm
519 9.1 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるデータの整合性検証不備に関する脆弱性 CWE-354
データの整合性検証不備
CVE-2026-49230 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
520 5.4 警告
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-49231 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 7.5 HIGH
Network
rubyconcurrency concurrent_ruby concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is cau… New CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-54904 2026-06-27 04:26 2026-06-25 Show GitHub Exploit DB Packet Storm
532 5.3 MEDIUM
Network
encode starlette Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating… New CWE-706
 Use of Incorrectly-Resolved Name or Reference
CVE-2026-54282 2026-06-27 04:18 2026-06-23 Show GitHub Exploit DB Packet Storm
533 7.5 HIGH
Network
encode starlette Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are … New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-54283 2026-06-27 04:16 2026-06-23 Show GitHub Exploit DB Packet Storm
534 - - - Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the requi… New CWE-863
 Incorrect Authorization
CVE-2026-54573 2026-06-27 04:16 2026-06-26 Show GitHub Exploit DB Packet Storm
535 2.2 LOW
Local
- - Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly create or rewrite this … New CWE-367
CWE-732
 Time-of-check Time-of-use (TOCTOU) Race Condition
 Incorrect Permission Assignment for Critical Resource
CVE-2026-54327 2026-06-27 04:16 2026-06-24 Show GitHub Exploit DB Packet Storm
536 5.8 MEDIUM
Local
- - K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functi… New CWE-22
Path Traversal
CVE-2026-54250 2026-06-27 04:16 2026-06-26 Show GitHub Exploit DB Packet Storm
537 7.5 HIGH
Network
- - File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase t… New CWE-863
 Incorrect Authorization
CVE-2026-54091 2026-06-27 04:16 2026-06-26 Show GitHub Exploit DB Packet Storm
538 7.1 HIGH
Network
- - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engin… New CWE-79
CWE-184
Cross-site Scripting
 Incomplete Blacklist
CVE-2026-54070 2026-06-27 04:16 2026-06-25 Show GitHub Exploit DB Packet Storm
539 5.5 MEDIUM
Network
snipeitapp snipe-it Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except … New CWE-863
 Incorrect Authorization
CVE-2026-48493 2026-06-27 04:16 2026-06-24 Show GitHub Exploit DB Packet Storm
540 5.3 MEDIUM
Network
- - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete an… New CWE-862
 Missing Authorization
CVE-2026-54029 2026-06-27 04:16 2026-06-26 Show GitHub Exploit DB Packet Storm