Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2411 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-23419 2026-04-27 10:52 2026-04-3 Show GitHub Exploit DB Packet Storm
2412 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおけるリソースのロックに関する脆弱性 CWE-667
不適切なロック
CVE-2026-23420 2026-04-27 10:52 2026-04-3 Show GitHub Exploit DB Packet Storm
2413 5.5 警告
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-23421 2026-04-27 10:52 2026-04-3 Show GitHub Exploit DB Packet Storm
2414 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-23422 2026-04-27 10:52 2026-04-3 Show GitHub Exploit DB Packet Storm
2415 5.7 警告
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows 仮想化ベース セキュリティ (VBS) のセキュリティ機能バイパスの脆弱性 CWE-822
信頼性のないポインタデリファレンス
CVE-2026-23670 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
2416 7 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows Server 2025
Microsoft Windows 11 24h2
Microsoft Wind…
AppLocker フィルター ドライバー (applockerfltr.sys) の特権昇格の脆弱性 CWE-362
競合状態
CVE-2026-25184 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
2417 7.1 重要
Network
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
リモート デスクトップのスプーフィングの脆弱性 CWE-357
危険な操作に対する不十分な警告
CVE-2026-26151 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
2418 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Microsoft Cryptographic Services の特権の昇格の脆弱性 CWE-922
重要な情報のセキュアでない格納
CVE-2026-26152 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
2419 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows 暗号化ファイル システム (EFS) の特権昇格の脆弱性 CWE-125
境界外読み取り
CVE-2026-26153 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
2420 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microso…
Windows Server Update Service (WSUS) の改ざんの脆弱性 CWE-20
不適切な入力確認
CVE-2026-26154 2026-04-27 10:52 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1221 5.0 MEDIUM
Network
linuxcontainers incus Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request a… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-35527 2026-05-8 02:06 2026-05-6 Show GitHub Exploit DB Packet Storm
1222 8.3 HIGH
Network
hcltech bigfix_service_management HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing in… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-30151 2026-05-8 02:06 2026-05-7 Show GitHub Exploit DB Packet Storm
1223 5.3 MEDIUM
Network
hcltech bigfix_service_management HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to… CWE-209
Information Exposure Through an Error Message
CVE-2025-31960 2026-05-8 02:05 2026-05-7 Show GitHub Exploit DB Packet Storm
1224 8.8 HIGH
Network
google chrome Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a cr… CWE-787
 Out-of-bounds Write
CVE-2026-7957 2026-05-8 02:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1225 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write permissions to persist profile configuration witho… CWE-862
 Missing Authorization
CVE-2026-43579 2026-05-8 02:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1226 9.1 CRITICAL
Network
openclaw openclaw OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can… CWE-184
 Incomplete Blacklist
CVE-2026-43578 2026-05-8 02:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1227 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions. Attackers can pivot into the local CDP origin and… CWE-862
 Missing Authorization
CVE-2026-43577 2026-05-8 02:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1228 7.7 HIGH
Network
openclaw openclaw OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocket… CWE-601
CWE-918
Open Redirect
Server-Side Request Forgery (SSRF) 
CVE-2026-43576 2026-05-8 02:04 2026-05-7 Show GitHub Exploit DB Packet Storm
1229 9.8 CRITICAL
Network
openclaw openclaw OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can acces… CWE-862
 Missing Authorization
CVE-2026-43575 2026-05-8 02:03 2026-05-7 Show GitHub Exploit DB Packet Storm
1230 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers … CWE-183
 Permissive List of Allowed Inputs
CVE-2026-43574 2026-05-8 02:03 2026-05-5 Show GitHub Exploit DB Packet Storm