Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
551 5.3 警告
Network
protobufjs project protobufjs-cli
protobufjs
protobufjs projectのprotobufjs-cli等の複数製品における複数の脆弱性 CWE-674
CWE-754
CVE-2026-54269 2026-06-26 11:55 2026-06-22 Show GitHub Exploit DB Packet Storm
552 5.3 警告
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-54270 2026-06-26 11:55 2026-06-22 Show GitHub Exploit DB Packet Storm
553 8.2 重要
Network
protobufjs project protobufjs-cli protobufjs projectのprotobufjs-cliにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-54271 2026-06-26 11:55 2026-06-22 Show GitHub Exploit DB Packet Storm
554 7.5 重要
Network
Astro Astro Astroにおける複数の脆弱性 CWE-20
CWE-918
CVE-2026-54299 2026-06-26 11:54 2026-06-22 Show GitHub Exploit DB Packet Storm
555 5.4 警告
Network
n8n n8n n8nにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-54303 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
556 10 緊急
Network
n8n n8n n8nにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-54309 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
557 9.9 緊急
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-54310 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
558 7.7 重要
Network
n8n n8n n8nにおける誤ったセッションへのデータ要素の漏えいに関する脆弱性 CWE-488
誤ったセッションへのデータ要素の漏えい
CVE-2026-54311 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
559 8.5 重要
Network
n8n n8n n8nにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 CWE-1321
オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染)
CVE-2026-54312 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
560 7.7 重要
Network
n8n n8n n8nにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-54313 2026-06-26 11:54 2026-06-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320731 9.8 CRITICAL
Network
mecha-cms mecha Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in … CWE-22
Path Traversal
CVE-2024-46446 2024-10-11 22:04 2024-10-8 Show GitHub Exploit DB Packet Storm
320732 6.5 MEDIUM
Network
shilpi client_dashboard This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by includin… NVD-CWE-Other
CVE-2024-47651 2024-10-11 06:01 2024-10-4 Show GitHub Exploit DB Packet Storm
320733 5.4 MEDIUM
Network
prontotools login_logout_shortcode The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitizati… CWE-79
Cross-site Scripting
CVE-2024-9421 2024-10-11 05:59 2024-10-4 Show GitHub Exploit DB Packet Storm
320734 5.4 MEDIUM
Network
acekyd display_medium_posts The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insuffici… CWE-79
Cross-site Scripting
CVE-2024-9445 2024-10-11 05:58 2024-10-4 Show GitHub Exploit DB Packet Storm
320735 5.4 MEDIUM
Network
davidartiss code_embed The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions… CWE-79
Cross-site Scripting
CVE-2024-8804 2024-10-11 05:56 2024-10-4 Show GitHub Exploit DB Packet Storm
320736 6.1 MEDIUM
Network
wpfactory quantity_dynamic_pricing_\&_bulk_discounts_for_woocommerce The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the … CWE-79
Cross-site Scripting
CVE-2024-9384 2024-10-11 05:52 2024-10-4 Show GitHub Exploit DB Packet Storm
320737 6.1 MEDIUM
Network
techbanker captcha_bank The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versio… CWE-79
Cross-site Scripting
CVE-2024-9375 2024-10-11 05:44 2024-10-4 Show GitHub Exploit DB Packet Storm
320738 5.4 MEDIUM
Network
wpblockshub wp_blocks_hub The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output … CWE-79
Cross-site Scripting
CVE-2024-9372 2024-10-11 05:36 2024-10-4 Show GitHub Exploit DB Packet Storm
320739 5.4 MEDIUM
Network
miguelmello aggregator_advanced_settings The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitizat… CWE-79
Cross-site Scripting
CVE-2024-9368 2024-10-11 05:30 2024-10-4 Show GitHub Exploit DB Packet Storm
320740 6.1 MEDIUM
Network
michaeluno auto_amazon_links The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL… CWE-79
Cross-site Scripting
CVE-2024-9349 2024-10-11 05:25 2024-10-4 Show GitHub Exploit DB Packet Storm