Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
61 9.8 緊急
Network
Rubyconcurrency Concurrent Ruby RubyconcurrencyのConcurrent Rubyにおける複数の脆弱性 New CWE-414
CWE-667
CVE-2026-54906 2026-06-29 11:23 2026-06-24 Show GitHub Exploit DB Packet Storm
62 9.8 緊急
Network
rtklib RTKLIB rtklibのRTKLIBにおける境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2026-56786 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
63 7.5 重要
Network
rtklib RTKLIB rtklibのRTKLIBにおける境界条件の判定に関する脆弱性 New CWE-193
境界条件の判定
CVE-2026-56787 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
64 7.1 重要
Local
rtklib RTKLIB rtklibのRTKLIBにおける境界外読み取りに関する脆弱性 New CWE-125
境界外読み取り
CVE-2026-56788 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
65 6.5 警告
Network
rtklib RTKLIB rtklibのRTKLIBにおけるヒープベースのバッファオーバーフローの脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-56789 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
66 2.6
Network
Nokogiri project Nokogiri Nokogiriにおける複数の脆弱性 New CWE-178
CWE-184
CWE-611
CVE-2026-57234 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
67 8.2 重要
Network
Nokogiri project Nokogiri Nokogiriにおける複数の脆弱性 New CWE-125
CWE-190
CVE-2026-57235 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
68 8.2 重要
Network
Nokogiri project Nokogiri Nokogiriにおける解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-57236 2026-06-29 11:23 2026-06-25 Show GitHub Exploit DB Packet Storm
69 4.3 警告
Network
Jenkins プロジェクト Priority Sorter JenkinsのPriority Sorterにおけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2026-57290 2026-06-29 11:23 2026-06-24 Show GitHub Exploit DB Packet Storm
70 5.4 警告
Network
Jenkins プロジェクト EC2 Fleet JenkinsのEC2 Fleetにおける認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2026-57294 2026-06-29 11:22 2026-06-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
320791 7.5 HIGH
Network
cisco meraki_z4c_firmware
meraki_z4_firmware
meraki_z3c_firmware
meraki_z3_firmware
meraki_vmx_firmware
meraki_mx600_firmware
meraki_mx450_firmware
meraki_mx400_firmware
meraki_mx25…
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in … CWE-400
 Uncontrolled Resource Consumption
CVE-2024-20500 2024-10-9 02:37 2024-10-3 Show GitHub Exploit DB Packet Storm
320792 - - - An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port. - CVE-2024-44439 2024-10-9 01:35 2024-10-5 Show GitHub Exploit DB Packet Storm
320793 5.4 MEDIUM
Network
memberful memberful The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all … CWE-79
Cross-site Scripting
CVE-2024-9242 2024-10-9 01:26 2024-10-4 Show GitHub Exploit DB Packet Storm
320794 4.8 MEDIUM
Network
wpbookingcalendar wp_booking_calendar The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and outp… CWE-79
Cross-site Scripting
CVE-2024-9306 2024-10-9 01:25 2024-10-4 Show GitHub Exploit DB Packet Storm
320795 6.1 MEDIUM
Network
plainware shiftcontroller The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input … CWE-79
Cross-site Scripting
CVE-2024-9435 2024-10-9 01:22 2024-10-4 Show GitHub Exploit DB Packet Storm
320796 5.4 MEDIUM
Network
sigmadevs easy_demo_importer The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due… CWE-79
Cross-site Scripting
CVE-2024-9071 2024-10-9 01:21 2024-10-4 Show GitHub Exploit DB Packet Storm
320797 4.3 MEDIUM
Adjacent
cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerabili… CWE-190
 Integer Overflow or Wraparound
CVE-2024-20434 2024-10-9 01:20 2024-09-26 Show GitHub Exploit DB Packet Storm
320798 5.4 MEDIUM
Network
remilia re\ The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping… CWE-79
Cross-site Scripting
CVE-2024-9271 2024-10-9 01:17 2024-10-4 Show GitHub Exploit DB Packet Storm
320799 6.5 MEDIUM
Network
cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. … CWE-311
Missing Encryption of Sensitive Data
CVE-2024-20515 2024-10-9 01:11 2024-10-3 Show GitHub Exploit DB Packet Storm
320800 6.1 MEDIUM
Network
tychesoftwares product_delivery_date_for_woocommerce The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all ve… CWE-79
Cross-site Scripting
CVE-2024-9345 2024-10-9 01:10 2024-10-4 Show GitHub Exploit DB Packet Storm