Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2371 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける一貫性のない実装を含む機能の使用に関する脆弱性 CWE-474
一貫性のない実装を含む機能の使用
CVE-2026-0902 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2372 5.4 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-0903 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2373 5.4 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-0904 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2374 9.8 緊急
Network
Google Google Chrome GoogleのGoogle Chromeにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-0905 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2375 9.8 緊急
Network
Google Google Chrome GoogleのGoogle Chromeにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-0906 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2376 9.8 緊急
Network
Google Google Chrome GoogleのGoogle Chromeにおけるユーザインターフェースにおける重要情報の誤った表示に関する脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2026-0907 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2377 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-0908 2026-02-2 19:38 2026-01-20 Show GitHub Exploit DB Packet Storm
2378 7.5 重要
Network
Eclipse Foundation Vert.x-Web Eclipse FoundationのVert.x-WebにおけるHTTP リクエストスマグリングに関する脆弱性 CWE-444
HTTP リクエストスマグリング
CVE-2026-1002 2026-02-2 19:38 2026-01-15 Show GitHub Exploit DB Packet Storm
2379 9.8 緊急
Network
D-Link Systems, Inc. DIR-823X ファームウェア D-Link CorporationのDIR-823X ファームウェアにおける複数の脆弱性 CWE-74
CWE-77
CWE-77
CVE-2026-1125 2026-02-2 19:38 2026-01-18 Show GitHub Exploit DB Packet Storm
2380 8.8 重要
Network
TOTOLINK a3700r ファームウェア TOTOLINKのa3700r ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-1143 2026-02-2 19:38 2026-01-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
131 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain unauthorized access through existing… Update CWE-613
 Insufficient Session Expiration
CVE-2026-41356 2026-04-29 23:08 2026-04-24 Show GitHub Exploit DB Packet Storm
132 7.1 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable … Update CWE-184
CWE-918
 Incomplete Blacklist
Server-Side Request Forgery (SSRF) 
CVE-2026-41361 2026-04-29 23:08 2026-04-24 Show GitHub Exploit DB Packet Storm
133 3.3 LOW
Local
openclaw openclaw OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by leve… Update CWE-214
 Invocation of Process Using Visible Sensitive Information
CVE-2026-41357 2026-04-29 22:57 2026-04-24 Show GitHub Exploit DB Packet Storm
134 5.9 MEDIUM
Network
opentelemetry opentelemetry OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if t… Update CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-40182 2026-04-29 22:52 2026-04-24 Show GitHub Exploit DB Packet Storm
135 8.8 HIGH
Network
openclaw openclaw OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Telegram configuration and cron persistence setti… Update CWE-269
 Improper Privilege Management
CVE-2026-41359 2026-04-29 22:44 2026-04-24 Show GitHub Exploit DB Packet Storm
136 8.8 HIGH
Network
- - Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s… New CWE-416
 Use After Free
CVE-2026-7363 2026-04-29 22:16 2026-04-29 Show GitHub Exploit DB Packet Storm
137 8.3 HIGH
Network
- - Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT… New CWE-416
 Use After Free
CVE-2026-7352 2026-04-29 22:16 2026-04-29 Show GitHub Exploit DB Packet Storm
138 8.3 HIGH
Network
- - Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. … New CWE-416
 Use After Free
CVE-2026-7350 2026-04-29 22:16 2026-04-29 Show GitHub Exploit DB Packet Storm
139 8.1 HIGH
Network
- - Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) New CWE-416
 Use After Free
CVE-2026-7347 2026-04-29 22:16 2026-04-29 Show GitHub Exploit DB Packet Storm
140 8.1 HIGH
Network
- - Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Hi… New CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-7346 2026-04-29 22:16 2026-04-29 Show GitHub Exploit DB Packet Storm