Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1961 7.1 重要
Network
OpenClaw OpenClaw OpenClawにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-41347 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1962 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41348 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1963 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41349 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1964 4.3 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41350 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1965 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるCapture-replay による認証回避に関する脆弱性 CWE-294
Capture-replayによる認証回避
CVE-2026-41351 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1966 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41352 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1967 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-41356 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1968 3.3
Local
OpenClaw OpenClaw OpenClawにおける重要な情報を使用しているプロセスの呼び出しに関する脆弱性 CWE-214
重要な情報を使用しているプロセスの呼び出し
CVE-2026-41357 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1969 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-41359 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
1970 7.1 重要
Network
OpenClaw OpenClaw OpenClawにおける複数の脆弱性 CWE-184
CWE-918
CVE-2026-41361 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313761 8.8 HIGH
Network
- - The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient … - CVE-2024-7827 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313762 - - - A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensit… - CVE-2024-7305 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313763 - - - BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero - CVE-2024-4785 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313764 - - - Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-I… - CVE-2024-35538 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313765 - - - Deserialization of Untrusted Data vulnerability in myCred allows Object Injection.This issue affects myCred: from n/a through 2.7.2. CWE-502
 Deserialization of Untrusted Data
CVE-2024-43354 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313766 - - - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder:… CWE-22
Path Traversal
CVE-2024-43345 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313767 - - - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through … CWE-22
Path Traversal
CVE-2024-43328 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313768 - - - Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7. CWE-862
 Missing Authorization
CVE-2024-43326 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313769 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This … CWE-79
Cross-site Scripting
CVE-2024-43317 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm
313770 - - - Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2. CWE-269
 Improper Privilege Management
CVE-2024-43311 2024-08-21 00:44 2024-08-20 Show GitHub Exploit DB Packet Storm