Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2611 8.1 重要
Network
Project Contour Contour Project ContourのContourにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41246 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2612 9.8 緊急
Network
std42 elfinder std42のelfinderにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-41247 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2613 7.5 重要
Network
joinmastodon Mastodon joinmastodonのMastodonにおける行動ワークフローに関する脆弱性 CWE-841
行動ワークフローの不適切な実施
CVE-2026-41259 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2614 9.1 緊急
Network
dgraph dgraph dgraphにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-41327 2026-04-30 11:01 2026-04-24 Show GitHub Exploit DB Packet Storm
2615 9.1 緊急
Network
dgraph dgraph dgraphにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-41328 2026-04-30 11:01 2026-04-24 Show GitHub Exploit DB Packet Storm
2616 3.7
Network
OpenClaw OpenClaw OpenClawにおけるインタラクション頻度の制御に関する脆弱性  CWE-799
インタラクション頻度の不適切な制御
CVE-2026-41333 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2617 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける安全でない失敗処理に関する脆弱性 CWE-636
安全でない失敗処理
CVE-2026-41334 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2618 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-41335 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2619 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-41336 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
2620 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41337 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314201 8.8 HIGH
Network
hamastar meetinghub_paperless_meetings A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary sy… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-6117 2024-08-31 02:41 2024-08-5 Show GitHub Exploit DB Packet Storm
314202 5.3 MEDIUM
Network
in2code powermail An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An un… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-45232 2024-08-31 01:34 2024-08-29 Show GitHub Exploit DB Packet Storm
314203 8.8 HIGH
Network
google chrome Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-843
Type Confusion
CVE-2024-8194 2024-08-31 01:34 2024-08-29 Show GitHub Exploit DB Packet Storm
314204 9.8 CRITICAL
Network
in2code powermail An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, re… NVD-CWE-Other
CVE-2024-45233 2024-08-31 01:33 2024-08-29 Show GitHub Exploit DB Packet Storm
314205 5.5 MEDIUM
Local
wireshark wireshark NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file CWE-787
 Out-of-bounds Write
CVE-2024-8250 2024-08-31 01:32 2024-08-29 Show GitHub Exploit DB Packet Storm
314206 6.1 MEDIUM
Network
nextbricks bricksore Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.… CWE-79
Cross-site Scripting
CVE-2024-43950 2024-08-31 01:20 2024-08-30 Show GitHub Exploit DB Packet Storm
314207 7.5 HIGH
Network
frrouting
redhat
frrouting
enterprise_linux
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value. NVD-CWE-noinfo
CVE-2024-44070 2024-08-31 01:19 2024-08-19 Show GitHub Exploit DB Packet Storm
314208 5.4 MEDIUM
Network
cryoutcreations tempera Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through 1.8… CWE-79
Cross-site Scripting
CVE-2024-43951 2024-08-31 01:17 2024-08-30 Show GitHub Exploit DB Packet Storm
314209 5.4 MEDIUM
Network
cryoutcreations esotera Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through 1.2… CWE-79
Cross-site Scripting
CVE-2024-43952 2024-08-31 01:16 2024-08-30 Show GitHub Exploit DB Packet Storm
314210 - - - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. - CVE-2024-8064 2024-08-31 01:15 2024-08-31 Show GitHub Exploit DB Packet Storm