Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4501 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8414 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4502 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8415 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4503 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8416 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4504 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-8417 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4505 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-8421 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4506 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-352
CWE-829
CVE-2026-8426 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4507 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8427 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4508 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-352
CWE-829
CVE-2026-8428 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4509 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8432 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
4510 8.8 重要
Network
Concrete CMS Concrete CMS Concrete CMSにおける複数の脆弱性 CWE-1275
CWE-352
CVE-2026-8433 2026-05-28 14:36 2026-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1961 7.2 HIGH
Network
- - The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated att… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-12095 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1962 4.3 MEDIUM
Network
- - The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings()… CWE-862
 Missing Authorization
CVE-2026-8614 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1963 4.3 MEDIUM
Network
- - The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is auth… CWE-862
 Missing Authorization
CVE-2026-8688 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1964 5.3 MEDIUM
Network
- - The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifyin… CWE-862
 Missing Authorization
CVE-2026-8690 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1965 8.8 HIGH
Network
- - The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOptio… CWE-862
 Missing Authorization
CVE-2026-4297 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1966 4.3 MEDIUM
Network
- - The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the… CWE-352
 Origin Validation Error
CVE-2026-6292 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1967 6.1 MEDIUM
Network
- - The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and ou… CWE-79
Cross-site Scripting
CVE-2026-8628 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1968 7.5 HIGH
Network
- - The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.… CWE-89
SQL Injection
CVE-2026-8705 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1969 6.1 MEDIUM
Network
- - The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on a funct… CWE-352
 Origin Validation Error
CVE-2026-8905 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1970 4.3 MEDIUM
Network
- - The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is auth… CWE-862
 Missing Authorization
CVE-2026-9616 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm