Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2801 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows TDI 翻訳ドライバー (tdx.sys) の特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27908 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2802 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows Search サービスの特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27909 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2803 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows インストーラーの特権の昇格の脆弱性 CWE-280
権限管理不備
CVE-2026-27910 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2804 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows ユーザー インターフェイス コアの特権昇格の脆弱性 CWE-362
CWE-416
CVE-2026-27911 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2805 8 重要
Adjacent
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microso…
Windows Kerberos の特権の昇格の脆弱性 CWE-285
不適切な認可
CVE-2026-27912 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2806 7.7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server 2012
Microsoft Windows Server 2016
Windows BitLocker セキュリティ機能バイパスの脆弱性 CWE-20
不適切な入力確認
CVE-2026-27913 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2807 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Microsoft 管理コンソールの特権昇格の脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-27914 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2808 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27915 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2809 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows UPnP Device Host の特権の昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27916 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
2810 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows WFP NDIS ライトウェイト フィルター ドライバー (wfplwfs.sys) の特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-27917 2026-04-24 11:32 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
31 7.8 HIGH
Local
- - OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution.… New CWE-427
 Uncontrolled Search Path Element
CVE-2026-45004 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
32 5.0 MEDIUM
Local
- - OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime… New CWE-441
Confused Deputy
CVE-2026-45003 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
33 5.3 MEDIUM
Network
- - OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally inf… New CWE-863
 Incorrect Authorization
CVE-2026-45002 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
34 7.1 HIGH
Network
- - OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p… New CWE-862
 Missing Authorization
CVE-2026-45001 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
35 5.0 MEDIUM
Network
- - OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45000 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
36 5.3 MEDIUM
Network
- - OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attacke… New CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-44999 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
37 5.4 MEDIUM
Network
- - OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restr… New CWE-863
 Incorrect Authorization
CVE-2026-44998 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
38 4.3 MEDIUM
Network
- - OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, contro… New CWE-266
 Incorrect Privilege Assignment
CVE-2026-44997 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
39 3.7 LOW
Network
- - OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence ag… New CWE-22
Path Traversal
CVE-2026-44996 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm
40 7.3 HIGH
Local
- - OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace con… New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-44995 2026-05-12 03:16 2026-05-12 Show GitHub Exploit DB Packet Storm