Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2331 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2023-53684 2026-02-5 15:47 2025-10-7 Show GitHub Exploit DB Packet Storm
2332 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2023-53685 2026-02-5 15:47 2025-10-7 Show GitHub Exploit DB Packet Storm
2333 5.5 警告
Local
Linux Linux Kernel LinuxのLinux KernelにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2023-53686 2026-02-5 15:47 2025-10-7 Show GitHub Exploit DB Packet Storm
2334 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2023-53687 2026-02-5 15:47 2025-10-7 Show GitHub Exploit DB Packet Storm
2335 9.8 緊急
Network
eXtplorer eXtplorer eXtplorerにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2023-54335 2026-02-5 15:47 2026-01-13 Show GitHub Exploit DB Packet Storm
2336 7.5 重要
Network
Progress Software Corporation MOVEit Transfer Progress Software CorporationのMOVEit Transferにおける未検証のパスワード変更に関する脆弱性 CWE-620
未検証のパスワード変更
CVE-2025-11235 2026-02-5 15:47 2026-01-7 Show GitHub Exploit DB Packet Storm
2337 8.8 重要
Network
デル Dell Unisphere for PowerMax Virtual Appliance
Dell Unisphere for PowerMax
デルのDell Unisphere for PowerMax等の複数製品におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-36588 2026-02-5 15:46 2026-01-22 Show GitHub Exploit DB Packet Storm
2338 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるゼロ除算に関する脆弱性 CWE-369
ゼロ除算
CVE-2025-39954 2026-02-5 15:46 2025-10-9 Show GitHub Exploit DB Packet Storm
2339 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-39955 2026-02-5 15:46 2025-10-9 Show GitHub Exploit DB Packet Storm
2340 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-39956 2026-02-5 15:46 2025-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 5.3 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attacker… CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-41407 2026-05-1 04:38 2026-04-29 Show GitHub Exploit DB Packet Storm
532 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context m… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41406 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
533 7.5 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicio… CWE-408
 Incorrect Behavior Order: Early Amplification
CVE-2026-41405 2026-05-1 04:37 2026-04-29 Show GitHub Exploit DB Packet Storm
534 7.3 HIGH
Network
nextchat nextchat A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulatio… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7178 2026-05-1 04:26 2026-04-28 Show GitHub Exploit DB Packet Storm
535 7.3 HIGH
Network
nextchat nextchat A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation re… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7177 2026-05-1 04:26 2026-04-28 Show GitHub Exploit DB Packet Storm
536 7.3 HIGH
Network
mozilla firefox
thunderbird
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have… CWE-119
CWE-787
Incorrect Access of Indexable Resource ('Range Error') 
 Out-of-bounds Write
CVE-2026-7323 2026-05-1 03:38 2026-04-29 Show GitHub Exploit DB Packet Storm
537 9.6 CRITICAL
Network
google chrome Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-7333 2026-05-1 03:30 2026-04-29 Show GitHub Exploit DB Packet Storm
538 8.8 HIGH
Network
google chrome Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-7334 2026-05-1 03:29 2026-04-29 Show GitHub Exploit DB Packet Storm
539 8.8 HIGH
Network
google chrome Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-7335 2026-05-1 03:29 2026-04-29 Show GitHub Exploit DB Packet Storm
540 8.8 HIGH
Network
google chrome Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-7336 2026-05-1 03:28 2026-04-29 Show GitHub Exploit DB Packet Storm