Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 12:21 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
361 7.1 重要
Local
Presire qSnapper PresireのqSnapperにおける複数の脆弱性 New CWE-303
CWE-863
CVE-2026-41049 2026-06-29 11:07 2026-06-22 Show GitHub Exploit DB Packet Storm
362 7.1 重要
Local
Docling Docling Doclingにおける複数の脆弱性 New CWE-409
CWE-611
CWE-776
CVE-2026-44018 2026-06-29 11:07 2026-06-26 Show GitHub Exploit DB Packet Storm
363 6.5 警告
Network
aten ATEN Unizon atenのATEN Unizonにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-9774 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
364 6.5 警告
Network
aten ATEN Unizon atenのATEN Unizonにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-9775 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
365 7.5 重要
Network
aten ATEN Unizon atenのATEN Unizonにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-9776 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
366 7.2 重要
Network
aten ATEN Unizon atenのATEN Unizonにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-9777 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
367 7.2 重要
Network
aten ATEN Unizon atenのATEN Unizonにおけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2026-9778 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
368 7.2 重要
Network
aten ATEN Unizon atenのATEN Unizonにおけるデジタル署名の検証に関する脆弱性 New CWE-347
デジタル署名の不適切な検証
CVE-2026-9779 2026-06-29 11:07 2026-06-24 Show GitHub Exploit DB Packet Storm
369 5.4 警告
Network
レッドハット Red Hat Directory Server
389 Directory Server
Red Hat Enterprise Linux
レッドハットの389 Directory Server等の複数製品における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2026-12528 2026-06-29 11:06 2026-06-17 Show GitHub Exploit DB Packet Storm
370 10 緊急
Network
WSO2 WSO2 API Manager WSO2のWSO2 API Managerにおけるサーバサイドのリクエストフォージェリの脆弱性 New CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-2053 2026-06-29 11:06 2026-06-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3791 6.5 MEDIUM
Network
apache http_server Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. CWE-125
Out-of-bounds Read
CVE-2026-43951 2026-06-11 13:00 2026-06-9 Show GitHub Exploit DB Packet Storm
3792 8.1 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. T… CWE-284
CWE-639
CWE-915
Improper Access Control
 Authorization Bypass Through User-Controlled Key
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-42863 2026-06-11 12:58 2026-06-9 Show GitHub Exploit DB Packet Storm
3793 5.0 MEDIUM
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The e… CWE-284
CWE-639
CWE-915
Improper Access Control
 Authorization Bypass Through User-Controlled Key
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-42862 2026-06-11 12:56 2026-06-9 Show GitHub Exploit DB Packet Storm
3794 9.6 CRITICAL
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. T… CWE-284
CWE-639
CWE-915
Improper Access Control
 Authorization Bypass Through User-Controlled Key
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-42861 2026-06-11 12:53 2026-06-9 Show GitHub Exploit DB Packet Storm
3795 5.4 MEDIUM
Network
microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CWE-79
Cross-site Scripting
CVE-2026-45468 2026-06-11 11:43 2026-06-10 Show GitHub Exploit DB Packet Storm
3796 4.3 MEDIUM
Network
buffalo open_xdmod OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request… CWE-284
NVD-CWE-noinfo
Improper Access Control
CVE-2026-45776 2026-06-11 06:07 2026-06-6 Show GitHub Exploit DB Packet Storm
3797 9.8 CRITICAL
Network
buffalo open_xdmod OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web s… CWE-78
OS Command 
CVE-2026-45777 2026-06-11 06:06 2026-06-6 Show GitHub Exploit DB Packet Storm
3798 5.4 MEDIUM
Network
buffalo open_xdmod OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abus… CWE-79
Cross-site Scripting
CVE-2026-45778 2026-06-11 06:05 2026-06-6 Show GitHub Exploit DB Packet Storm
3799 9.8 CRITICAL
Network
buffalo open_xdmod OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to… CWE-89
SQL Injection
CVE-2026-45779 2026-06-11 06:04 2026-06-6 Show GitHub Exploit DB Packet Storm
3800 6.8 MEDIUM
Physics
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
w…
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. CWE-284
NVD-CWE-noinfo
Improper Access Control
CVE-2026-45658 2026-06-11 05:59 2026-06-10 Show GitHub Exploit DB Packet Storm