Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3111 7.5 重要
Network
OpenClaw OpenClaw OpenClawにおけるインタラクション頻度の制御に関する脆弱性  CWE-799
インタラクション頻度の不適切な制御
CVE-2026-41346 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3112 7.1 重要
Network
OpenClaw OpenClaw OpenClawにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-41347 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3113 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41348 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3114 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41349 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3115 4.3 警告
Network
OpenClaw OpenClaw OpenClawにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41350 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3116 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるCapture-replay による認証回避に関する脆弱性 CWE-294
Capture-replayによる認証回避
CVE-2026-41351 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3117 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-41352 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3118 5.4 警告
Network
OpenClaw OpenClaw OpenClawにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-41356 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3119 3.3
Local
OpenClaw OpenClaw OpenClawにおける重要な情報を使用しているプロセスの呼び出しに関する脆弱性 CWE-214
重要な情報を使用しているプロセスの呼び出し
CVE-2026-41357 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
3120 8.8 重要
Network
OpenClaw OpenClaw OpenClawにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-41359 2026-04-30 11:00 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1521 4.8 MEDIUM
Network
- - Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another adminis… CWE-79
Cross-site Scripting
CVE-2026-42948 2026-05-14 00:47 2026-05-13 Show GitHub Exploit DB Packet Storm
1522 4.3 MEDIUM
Network
- - ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may be… CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-42950 2026-05-14 00:47 2026-05-13 Show GitHub Exploit DB Packet Storm
1523 4.3 MEDIUM
Network
- - ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to… CWE-344
 Use of Invariant Value in Dynamically Changing Context
CVE-2026-42961 2026-05-14 00:47 2026-05-13 Show GitHub Exploit DB Packet Storm
1524 8.2 HIGH
Network
- - nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the librar… CWE-121
Stack-based Buffer Overflow
CVE-2026-29972 2026-05-14 00:46 2026-05-9 Show GitHub Exploit DB Packet Storm
1525 6.5 MEDIUM
Local
- - Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim … CWE-88
Argument Injection
CVE-2026-45181 2026-05-14 00:46 2026-05-10 Show GitHub Exploit DB Packet Storm
1526 2.2 LOW
Local
- - GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let syste… CWE-441
Confused Deputy
CVE-2026-45182 2026-05-14 00:46 2026-05-10 Show GitHub Exploit DB Packet Storm
1527 6.5 MEDIUM
Local
- - Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-45184 2026-05-14 00:46 2026-05-10 Show GitHub Exploit DB Packet Storm
1528 8.1 HIGH
Network
- - Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/s… CWE-78
OS Command 
CVE-2026-30635 2026-05-14 00:46 2026-05-12 Show GitHub Exploit DB Packet Storm
1529 8.8 HIGH
Network
- - EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient… CWE-77
Command Injection
CVE-2026-36734 2026-05-14 00:46 2026-05-12 Show GitHub Exploit DB Packet Storm
1530 7.3 HIGH
Network
- - An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function CWE-94
Code Injection
CVE-2026-37630 2026-05-14 00:46 2026-05-12 Show GitHub Exploit DB Packet Storm