Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3421 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41381 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3422 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41382 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3423 8.1 重要
Network
OpenClaw OpenClaw OpenClawにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41383 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3424 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおけるシステム構成または設定の外部制御に関する脆弱性 CWE-15
システム構成または設定の外部制御
CVE-2026-41384 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3425 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける重要な情報の平文保存に関する脆弱性 CWE-312
重要な情報の平文保存
CVE-2026-41385 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3426 9.8 緊急
Network
OpenClaw OpenClaw OpenClawにおける特権 API の不適切な使用に関する脆弱性 CWE-648
特権 API の不適切な使用
CVE-2026-41386 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3427 6.5 警告
Network
Wazuh Inc. Wazuh Wazuh Inc.のWazuhにおける複数の脆弱性 CWE-124
CWE-191
CVE-2026-41499 2026-05-7 12:04 2026-04-29 Show GitHub Exploit DB Packet Storm
3428 7.7 重要
Network
getoutline outline getoutlineのoutlineにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-41649 2026-05-7 12:04 2026-04-28 Show GitHub Exploit DB Packet Storm
3429 7.5 重要
Network
PostgreSQL.org PostgreSQL JDBC ドライバ PostgreSQL.orgのPostgreSQL JDBC ドライバにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-42198 2026-05-7 12:04 2026-04-29 Show GitHub Exploit DB Packet Storm
3430 8.1 重要
Network
FreeBSD FreeBSD FreeBSDにおける引用構文の無害化に関する脆弱性 CWE-149
引用構文の不適切な無害化
CVE-2026-42511 2026-05-7 12:04 2026-04-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317111 7.5 HIGH
Network
gitlab gitlab ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of s… CWE-1333
 Inefficient Regular Expression Complexity
CVE-2024-2800 2024-09-18 21:42 2024-08-8 Show GitHub Exploit DB Packet Storm
317112 5.4 MEDIUM
Network
gitlab gitlab A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When view… CWE-79
Cross-site Scripting
CVE-2024-4207 2024-09-18 21:41 2024-08-8 Show GitHub Exploit DB Packet Storm
317113 8.8 HIGH
Network
google
microsoft
chrome
edge_chromium
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-787
 Out-of-bounds Write
CVE-2024-7965 2024-09-18 21:40 2024-08-22 Show GitHub Exploit DB Packet Storm
317114 8.8 HIGH
Network
redhat openshift_data_science
openshift_ai
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option … NVD-CWE-Other
CVE-2024-7557 2024-09-18 16:15 2024-08-12 Show GitHub Exploit DB Packet Storm
317115 6.7 MEDIUM
Local
microsoft windows_10_1507
windows_10_1809
windows_server_2019
windows_server_2022
windows_11_21h2
windows_10_21h2
windows_11_22h2
windows_10_22h2
windows_11_23h2
windows_server_2022_…
Summary: Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machin… NVD-CWE-Other
CVE-2024-21302 2024-09-18 09:15 2024-08-8 Show GitHub Exploit DB Packet Storm
317116 7.5 HIGH
Network
containers aardvark-dns A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open… NVD-CWE-noinfo
CVE-2024-8418 2024-09-18 05:15 2024-09-5 Show GitHub Exploit DB Packet Storm
317117 4.3 MEDIUM
Network
imagerecycle imagerecycle_pdf_\&_image_compression The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valid… CWE-352
 Origin Validation Error
CVE-2024-8120 2024-09-18 05:07 2024-08-24 Show GitHub Exploit DB Packet Storm
317118 4.8 MEDIUM
Network
cleversoft clever_addons_for_elementor Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons … CWE-79
Cross-site Scripting
CVE-2024-43324 2024-09-18 05:04 2024-08-18 Show GitHub Exploit DB Packet Storm
317119 6.1 MEDIUM
Network
orbisius child_theme_creator Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Chil… CWE-79
Cross-site Scripting
CVE-2024-43276 2024-09-18 05:00 2024-08-18 Show GitHub Exploit DB Packet Storm
317120 5.4 MEDIUM
Network
cpothemes allegiant Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Chill Allegiant allegiant allows Stored XSS.This issue affects Allegiant: from n/a thro… CWE-79
Cross-site Scripting
CVE-2024-43329 2024-09-18 04:59 2024-08-18 Show GitHub Exploit DB Packet Storm