Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
521 3.3
Local
pypdf project pypdf pypdf projectのpypdfにおけるアルゴリズムの複雑さに関する脆弱性 CWE-407
アルゴリズムの複雑性
CVE-2026-49460 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
522 5.5 警告
Local
pypdf project pypdf pypdf projectのpypdfにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-49461 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
523 9.8 緊急
Network
litellm litellm LiteLLMにおけるスプーフィングによる認証回避に関する脆弱性 CWE-290
スプーフィングによる認証回避
CVE-2026-49468 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
524 5.4 警告
Network
Eclipse Foundation Eclipse Open VSX Eclipse FoundationのEclipse Open VSXにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4983 2026-06-26 11:56 2026-06-23 Show GitHub Exploit DB Packet Storm
525 9.3 緊急
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-49871 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
526 8.1 重要
Network
Apache Software Foundation APISIX Apache Software FoundationのAPISIXにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-49872 2026-06-26 11:56 2026-06-19 Show GitHub Exploit DB Packet Storm
527 5.4 警告
Network
Mattermost, Inc. Mattermost Server Mattermost, Inc.のMattermost Serverにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-5139 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
528 7.5 重要
Network
VoidZero Inc.
vitejs
Vite+
vite
vitejs等の複数ベンダの製品における複数の脆弱性 CWE-200
CWE-22
CVE-2026-53571 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
529 7.5 重要
Network
vLLM vLLM vLLMにおける複数の脆弱性 CWE-200
CWE-681
CVE-2026-53923 2026-06-26 11:56 2026-06-22 Show GitHub Exploit DB Packet Storm
530 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-54006 2026-06-26 11:56 2026-06-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320681 - - - IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permis… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2024-47815 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320682 - - - A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. - CVE-2024-9470 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320683 - - - A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of ser… - CVE-2024-9468 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320684 7.4 HIGH
Network
- - Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector CWE-200
Information Exposure
CVE-2024-43610 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320685 - - - ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS p… CWE-79
CWE-80
Cross-site Scripting
Basic XSS
CVE-2024-47812 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320686 - - - Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-47813 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320687 - - - Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The ru… CWE-670
 Always-Incorrect Control Flow Implementation
CVE-2024-47763 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320688 - - - Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, rega… - CVE-2024-42988 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320689 - - - DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrar… - CVE-2024-46316 2024-10-10 21:51 2024-10-10 Show GitHub Exploit DB Packet Storm
320690 5.5 MEDIUM
Local
- - Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to byp… CWE-125
Out-of-bounds Read
CVE-2024-47420 2024-10-10 21:51 2024-10-9 Show GitHub Exploit DB Packet Storm