Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3251 3.3
Local
GPAC GPAC GPACにおける複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2026-1415 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3252 3.3
Local
GPAC GPAC GPACにおける複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2026-1416 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3253 3.3
Local
GPAC GPAC GPACにおける複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2026-1417 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3254 7.8 重要
Local
GPAC GPAC GPACにおける複数の脆弱性 CWE-119
CWE-787
CWE-787
CVE-2026-1418 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3255 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. ac23 ファームウェア Shenzhen Tenda Technology Co.,Ltd.のac23 ファームウェアにおける複数の脆弱性 CWE-119
CWE-120
CVE-2026-1420 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3256 7.2 重要
Network
PHPGurukul News Portal Project in PHP and MySql PHPGurukulのNews Portal Project in PHP and MySqlにおける複数の脆弱性 CWE-284
CWE-434
CVE-2026-1424 2026-01-29 15:59 2026-01-26 Show GitHub Exploit DB Packet Storm
3257 7.2 重要
Network
D-Link Systems, Inc. DIR-615 ファームウェア D-Link CorporationのDIR-615 ファームウェアにおける複数の脆弱性 CWE-77
CWE-78
CWE-78
CVE-2026-1448 2026-01-29 15:59 2026-01-27 Show GitHub Exploit DB Packet Storm
3258 8.2 重要
Network
Apache Software Foundation Apache Solr Apache Software FoundationのApache Solrにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-22022 2026-01-29 15:59 2026-01-21 Show GitHub Exploit DB Packet Storm
3259 5.4 警告
Network
humansignal label studio humansignalのlabel studioにおける複数の脆弱性 CWE-284
CWE-79
CWE-79
CVE-2026-22033 2026-01-29 15:59 2026-01-12 Show GitHub Exploit DB Packet Storm
3260 7.5 重要
Network
Enhancesoft LLC. osTicket Enhancesoft LLC.のosTicketにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-22200 2026-01-29 15:59 2026-01-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
101 8.8 HIGH
Network
sailpoint identityiq This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned… Update CWE-863
 Incorrect Authorization
CVE-2026-5712 2026-05-5 21:48 2026-04-30 Show GitHub Exploit DB Packet Storm
102 7.1 HIGH
Local
dell dell\/alienware_purchased_apps Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could p… Update CWE-59
Link Following
CVE-2026-27105 2026-05-5 21:37 2026-04-30 Show GitHub Exploit DB Packet Storm
103 6.5 MEDIUM
Network
- - The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload pat… New CWE-22
Path Traversal
CVE-2026-6262 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
104 8.8 HIGH
Network
- - The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-6261 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
105 6.5 MEDIUM
Network
- - OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers … New CWE-183
 Permissive List of Allowed Inputs
CVE-2026-43574 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
106 7.7 HIGH
Network
- - OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact wi… New CWE-862
CWE-918
 Missing Authorization
Server-Side Request Forgery (SSRF) 
CVE-2026-43573 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
107 5.3 MEDIUM
Network
- - OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass … New CWE-862
 Missing Authorization
CVE-2026-43572 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
108 8.8 HIGH
Network
- - OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can expl… New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-43571 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
109 6.5 MEDIUM
Network
- - OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Atta… New CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-43570 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm
110 8.8 HIGH
Network
- - OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shado… New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-43569 2026-05-5 21:16 2026-05-5 Show GitHub Exploit DB Packet Storm