Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2491 7.5 重要
Network
OpenClaw OpenClaw OpenClawにおける暗号化処理の不備に関する脆弱性 CWE-325
暗号化処理の不備
CVE-2026-41395 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2492 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-41396 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2493 9.6 緊急
Network
OpenClaw OpenClaw OpenClawにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-41397 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2494 4 警告
Local
OpenClaw OpenClaw OpenClawにおけるセキュリティ決定の信頼できない入力への依存に関する脆弱性 CWE-807
セキュリティ決定の信頼できない入力への依存
CVE-2026-41403 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2495 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41404 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2496 7.5 重要
Network
OpenClaw OpenClaw OpenClawにおける不適切な動作順序(早期増幅)に関する脆弱性 CWE-408
不適切な動作順序(早期増幅)
CVE-2026-41405 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2497 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41406 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2498 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-41407 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2499 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-41408 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
2500 4.3 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41910 2026-05-7 12:29 2026-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1311 8.1 HIGH
Network
- - Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in … CWE-863
 Incorrect Authorization
CVE-2026-44633 2026-05-15 23:44 2026-05-15 Show GitHub Exploit DB Packet Storm
1312 - - - Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, … CWE-20
CWE-22
 Improper Input Validation 
Path Traversal
CVE-2026-44522 2026-05-15 23:44 2026-05-15 Show GitHub Exploit DB Packet Storm
1313 9.3 CRITICAL
Network
- - PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An u… CWE-79
Cross-site Scripting
CVE-2026-44212 2026-05-15 23:30 2026-05-15 Show GitHub Exploit DB Packet Storm
1314 5.4 MEDIUM
Network
- - Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script … CWE-79
Cross-site Scripting
CVE-2026-24662 2026-05-15 23:30 2026-05-15 Show GitHub Exploit DB Packet Storm
1315 8.1 HIGH
Network
- - Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected pr… CWE-352
 Origin Validation Error
CVE-2026-28761 2026-05-15 23:30 2026-05-15 Show GitHub Exploit DB Packet Storm
1316 6.5 MEDIUM
Network
pyload-ng_project pyload-ng pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_… CWE-22
CWE-36
Path Traversal
 Absolute Path Traversal
CVE-2026-42315 2026-05-15 23:29 2026-05-12 Show GitHub Exploit DB Packet Storm
1317 5.5 MEDIUM
Local
microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. CWE-22
CWE-23
Path Traversal
 Relative Path Traversal
CVE-2026-41612 2026-05-15 23:25 2026-05-13 Show GitHub Exploit DB Packet Storm
1318 8.8 HIGH
Network
microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. CWE-78
CWE-384
OS Command 
 Session Fixation
CVE-2026-41613 2026-05-15 23:23 2026-05-13 Show GitHub Exploit DB Packet Storm
1319 7.5 HIGH
Network
webtechnologies changedetection changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vu… CWE-73
 External Control of File Name or Path
CVE-2026-43891 2026-05-15 23:20 2026-05-13 Show GitHub Exploit DB Packet Storm
1320 6.7 MEDIUM
Local
fortinet fortiap
fortiap-w2
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versi… CWE-78
OS Command 
CVE-2025-53870 2026-05-15 23:15 2026-05-13 Show GitHub Exploit DB Packet Storm