Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192611 7.5 重要
Network
IBM - IBM Cognos TM1 におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-3036 2017-05-18 18:29 2016-03-9 Show GitHub Exploit DB Packet Storm
192612 5.4 警告
Network
IBM - IBM Marketing Platform におけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2016-0228 2017-05-18 18:29 2017-04-13 Show GitHub Exploit DB Packet Storm
192613 6.5 警告
Network
ImageMagick - ImageMagick の ept.c の ReadEPTImage 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-8357 2017-05-18 18:24 2017-04-27 Show GitHub Exploit DB Packet Storm
192614 6.5 警告
Network
ImageMagick - ImageMagick の sun.c の ReadSUNImage 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-8356 2017-05-18 18:24 2017-04-27 Show GitHub Exploit DB Packet Storm
192615 5.5 警告
Local
ImageWorsener project - ImageWorsener の libimageworsener.a の imagew-gif.c の iwgif_read_image 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-369
ゼロ除算
CVE-2017-7962 2017-05-18 18:19 2017-04-17 Show GitHub Exploit DB Packet Storm
192616 5.5 警告
Local
ImageWorsener project - ImageWorsener の libimageworsener.a の imagew-gif.c の iw_read_gif_file 関数における利用可能なメモリ量を消費される脆弱性 CWE-400
リソースの枯渇
CVE-2017-7940 2017-05-18 18:19 2017-04-17 Show GitHub Exploit DB Packet Storm
192617 5.5 警告
Local
ImageWorsener project - ImageWorsener の libimageworsener.a の imagew-pnm.c の read_next_pam_token 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2017-7939 2017-05-18 18:18 2017-04-9 Show GitHub Exploit DB Packet Storm
192618 5.5 警告
Local
Huawei - Huawei P7 および P8 ALE-UL00 におけるサービス運用妨害 (DoS) の脆弱性 CWE-275
パーミッションの問題
CVE-2015-8223 2017-05-18 17:17 2015-11-6 Show GitHub Exploit DB Packet Storm
192619 5.5 警告
Local
Huawei - Huawei P7 および P8 ALE-UL00 におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-7740 2017-05-18 17:17 2015-11-6 Show GitHub Exploit DB Packet Storm
192620 7.5 重要
Network
MongoDB Inc. - MongoDB の mongod におけるサービス運用妨害 (DoS) の脆弱性 CWE-400
リソースの枯渇
CVE-2016-3104 2017-05-18 16:51 2016-06-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
481 6.1 MEDIUM
Local
openclaw openclaw OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Atta… New CWE-184
 Incomplete Blacklist
CVE-2026-41391 2026-05-1 05:42 2026-04-29 Show GitHub Exploit DB Packet Storm
482 7.3 HIGH
Local
openclaw openclaw OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers… New CWE-807
 Reliance on Untrusted Inputs in a Security Decision
CVE-2026-41390 2026-05-1 05:38 2026-04-29 Show GitHub Exploit DB Packet Storm
483 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate r… New CWE-372
 Incomplete Internal State Distinction
CVE-2026-41388 2026-05-1 05:37 2026-04-29 Show GitHub Exploit DB Packet Storm
484 7.8 HIGH
Local
openclaw openclaw OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment… New CWE-183
 Permissive List of Allowed Inputs
CVE-2026-41387 2026-05-1 05:36 2026-04-29 Show GitHub Exploit DB Packet Storm
485 7.6 HIGH
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser inter… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41912 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
486 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file and u… New CWE-22
Path Traversal
CVE-2026-41911 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
487 4.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist mod… New CWE-863
 Incorrect Authorization
CVE-2026-41910 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
488 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk spa… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41408 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
489 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attacker… New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-41407 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
490 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context m… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41406 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm