Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251011 4.3 警告 アップル
Google
- Google Chrome における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-2800 2011-11-21 11:53 2011-08-2 Show GitHub Exploit DB Packet Storm
251012 7.5 危険 アップル
Google
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2799 2011-11-21 11:53 2011-08-2 Show GitHub Exploit DB Packet Storm
251013 5 警告 Google - Google Chrome における詳細不明な脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2798 2011-11-21 11:52 2011-08-2 Show GitHub Exploit DB Packet Storm
251014 7.5 危険 アップル
Google
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2797 2011-11-21 11:52 2011-08-2 Show GitHub Exploit DB Packet Storm
251015 7.5 危険 Google - Google Chrome で利用される Skia におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2796 2011-11-21 11:50 2011-08-2 Show GitHub Exploit DB Packet Storm
251016 5.8 警告 Google - Google Chrome におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2795 2011-11-21 11:49 2011-08-2 Show GitHub Exploit DB Packet Storm
251017 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2793 2011-11-21 11:48 2011-08-2 Show GitHub Exploit DB Packet Storm
251018 7.5 危険 アップル
Google
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2792 2011-11-21 11:47 2011-08-2 Show GitHub Exploit DB Packet Storm
251019 7.5 危険 アップル
Google
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2790 2011-11-21 11:45 2011-08-2 Show GitHub Exploit DB Packet Storm
251020 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2789 2011-11-21 11:44 2011-08-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2471 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate r… CWE-372
 Incomplete Internal State Distinction
CVE-2026-41388 2026-05-1 05:37 2026-04-29 Show GitHub Exploit DB Packet Storm
2472 7.8 HIGH
Local
openclaw openclaw OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment… CWE-183
 Permissive List of Allowed Inputs
CVE-2026-41387 2026-05-1 05:36 2026-04-29 Show GitHub Exploit DB Packet Storm
2473 7.6 HIGH
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser inter… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41912 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
2474 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file and u… CWE-22
Path Traversal
CVE-2026-41911 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
2475 4.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist mod… CWE-863
 Incorrect Authorization
CVE-2026-41910 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
2476 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk spa… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41408 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
2477 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attacker… CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-41407 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
2478 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context m… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41406 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
2479 7.5 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicio… CWE-408
 Incorrect Behavior Order: Early Amplification
CVE-2026-41405 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
2480 7.3 HIGH
Network
nextchat nextchat A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulatio… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7178 2026-05-1 04:26 2026-04-28 Show GitHub Exploit DB Packet Storm