Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198881 7.5 重要
Network
The PHP Group - PHP の ext/wddx/wddx.c の php_wddx_push_element 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-7418 2016-10-7 16:40 2016-09-15 Show GitHub Exploit DB Packet Storm
198882 9.8 緊急
Network
The PHP Group - PHP の ext/wddx/wddx.c の wddx_stack_destroy 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-7413 2016-10-7 16:40 2016-09-15 Show GitHub Exploit DB Packet Storm
198883 8.8 重要
Network
The PHP Group - PHP の ext/zip/zip_stream.c の php_stream_zip_opener 関数における整数オーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-6297 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198884 9.8 緊急
Network
The PHP Group - PHP で使用される xmlrpc-epi の simplestring.c の simplestring_addn 関数における整数符号エラーの脆弱性 CWE-119
バッファエラー
CVE-2016-6296 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198885 9.8 緊急
Network
The PHP Group - PHP の ext/snmp/snmp.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-6295 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198886 9.8 緊急
Network
The PHP Group - PHP の ext/intl/locale/locale_methods.c の locale_accept_from_http 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-6294 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198887 6.5 警告
Network
The PHP Group - PHP の ext/exif/exif.c の exif_process_user_comment 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-6292 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198888 9.8 緊急
Network
The PHP Group - PHP の ext/exif/exif.c の exif_process_IFD_in_MAKERNOTE 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-6291 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198889 9.8 緊急
Network
The PHP Group - PHP の ext/session/session.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-6290 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
198890 7.8 重要
Local
The PHP Group - PHP の TSRM/tsrm_virtual_cwd.c の virtual_file_ex 関数における整数オーバーフローの脆弱性 CWE-Other
その他
CVE-2016-6289 2016-10-7 16:37 2016-07-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
371 7.6 HIGH
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser inter… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-41912 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
372 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file and u… New CWE-22
Path Traversal
CVE-2026-41911 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
373 4.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist mod… New CWE-863
 Incorrect Authorization
CVE-2026-41910 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
374 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk spa… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-41408 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
375 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attacker… New CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-41407 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
376 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context m… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41406 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
377 7.5 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicio… New CWE-408
 Incorrect Behavior Order: Early Amplification
CVE-2026-41405 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
378 7.3 HIGH
Network
nextchat nextchat A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulatio… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7178 2026-05-1 04:26 2026-04-28 Show GitHub Exploit DB Packet Storm
379 7.3 HIGH
Network
nextchat nextchat A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation re… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7177 2026-05-1 04:26 2026-04-28 Show GitHub Exploit DB Packet Storm
380 7.3 HIGH
Network
mozilla firefox
thunderbird
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have… New CWE-119
CWE-787
Incorrect Access of Indexable Resource ('Range Error') 
 Out-of-bounds Write
CVE-2026-7323 2026-05-1 03:38 2026-04-29 Show GitHub Exploit DB Packet Storm