Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
208541 5 警告 Novell
Digia
- QT の QtGui の BMP デコーダにおけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2015-0295 2015-03-27 11:06 2015-02-27 Show GitHub Exploit DB Packet Storm
208542 7.2 危険 アルバネットワークス株式会社 - Remote Access Point モードの Aruba アクセスポイント上で稼動する ArubaOS の "RAP console" 機能における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2015-1388 2015-03-27 11:00 2015-03-18 Show GitHub Exploit DB Packet Storm
208543 4.3 警告 Apache Software Foundation
アップル
サイバートラスト株式会社
ヒューレット・パッカード
サン・マイクロシステムズ
VMware
レッドハット
- Apache Tomcat の HttpServletResponse.sendError メソッドに関するクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1232 2015-03-26 17:55 2008-08-3 Show GitHub Exploit DB Packet Storm
208544 6.8 警告 ProFTPD Project - ProFTPD の sql_prepare_where 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-4652 2015-03-26 17:54 2010-11-18 Show GitHub Exploit DB Packet Storm
208545 4.3 警告 アップル
Apache Software Foundation
- Apache HTTP Server の mod_dav.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1896 2015-03-26 17:54 2013-07-10 Show GitHub Exploit DB Packet Storm
208546 5 警告 日本電気
Apache Software Foundation
アップル
サイバートラスト株式会社
富士通
ヒューレット・パッカード
サン・マイクロシステムズ
VMware
レッドハット
- Apache Tomcat の RequestDispatcher に関するディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2370 2015-03-26 17:43 2008-08-3 Show GitHub Exploit DB Packet Storm
208547 2.6 注意 オラクル - Oracle Java SE における Deployment に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-4208 2015-03-26 17:43 2014-07-15 Show GitHub Exploit DB Packet Storm
208548 7.5 危険 IBM - IBM WebSphere Real Time などで使用される IBM Java 仮想マシンにおける権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2014-3086 2015-03-26 17:42 2014-07-17 Show GitHub Exploit DB Packet Storm
208549 6.9 警告 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE における Deployment に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0403 2015-03-26 17:36 2015-01-20 Show GitHub Exploit DB Packet Storm
208550 5 警告 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE における Libraries に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-0400 2015-03-26 17:36 2015-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 7.5 HIGH
Network
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.recv_io.credits.available The logic off managing recv credits by counting posted recv_i… Update NVD-CWE-Other
CVE-2026-31538 2026-04-29 03:59 2026-04-25 Show GitHub Exploit DB Packet Storm
2 9.8 CRITICAL
Network
std42 elfinder elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background … Update CWE-78
OS Command 
CVE-2026-41247 2026-04-29 03:57 2026-04-24 Show GitHub Exploit DB Packet Storm
3 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. Attackers can re-enc… Update CWE-294
Authentication Bypass by Capture-replay 
CVE-2026-41351 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
4 4.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to enforce configured tools.sessions.visibility restrictions for unsandboxed invoc… Update CWE-863
 Incorrect Authorization
CVE-2026-41350 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
5 7.1 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by s… Update CWE-352
 Origin Validation Error
CVE-2026-41347 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
6 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cross-origin redirects. Attackers can exploit this by… Update CWE-522
 Insufficiently Protected Credentials
CVE-2026-41345 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
7 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook e… Update CWE-799
 Improper Control of Interaction Frequency
CVE-2026-41343 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
8 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exp… Update CWE-372
 Incomplete Internal State Distinction
CVE-2026-41340 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
9 5.0 MEDIUM
Local
openclaw openclaw OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defenses. Attackers can exploit check-then-act pattern… Update CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-41338 2026-04-29 03:56 2026-04-24 Show GitHub Exploit DB Packet Storm
10 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attackers to mutate in-process callback origin before replay rejection. Attackers wi… Update CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-41337 2026-04-29 03:55 2026-04-24 Show GitHub Exploit DB Packet Storm