Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3501 7.5 重要
Network
joinmastodon Mastodon joinmastodonのMastodonにおける行動ワークフローに関する脆弱性 CWE-841
行動ワークフローの不適切な実施
CVE-2026-41259 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3502 9.1 緊急
Network
dgraph dgraph dgraphにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-41327 2026-04-30 11:01 2026-04-24 Show GitHub Exploit DB Packet Storm
3503 9.1 緊急
Network
dgraph dgraph dgraphにおけるデータクエリロジックの特殊要素の不適切な中立化に関する脆弱性 CWE-943
データクエリロジックの特殊要素の不適切な中立化
CVE-2026-41328 2026-04-30 11:01 2026-04-24 Show GitHub Exploit DB Packet Storm
3504 3.7
Network
OpenClaw OpenClaw OpenClawにおけるインタラクション頻度の制御に関する脆弱性  CWE-799
インタラクション頻度の不適切な制御
CVE-2026-41333 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3505 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける安全でない失敗処理に関する脆弱性 CWE-636
安全でない失敗処理
CVE-2026-41334 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3506 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2026-41335 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3507 7.8 重要
Local
OpenClaw OpenClaw OpenClawにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-41336 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3508 5.3 警告
Network
OpenClaw OpenClaw OpenClawにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41337 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3509 5 警告
Local
OpenClaw OpenClaw OpenClawにおけるTime-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-41338 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
3510 6.5 警告
Network
OpenClaw OpenClaw OpenClawにおける不完全な内部状態の区別に関する脆弱性 CWE-372
不完全な内部状態の区別
CVE-2026-41340 2026-04-30 11:01 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1421 9.8 CRITICAL
Network
- - Reserved. Details will be published at disclosure. CWE-20
 Improper Input Validation 
CVE-2026-45392 2026-05-15 21:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1422 9.8 CRITICAL
Network
- - Reserved. Details will be published at disclosure. CWE-20
 Improper Input Validation 
CVE-2026-45391 2026-05-15 21:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1423 9.6 CRITICAL
Network
- - Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi… CWE-459
 Incomplete Cleanup
CVE-2026-34263 2026-05-15 21:17 2026-05-12 Show GitHub Exploit DB Packet Storm
1424 - - - Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. … CWE-290
 Authentication Bypass by Spoofing
CVE-2026-24899 2026-05-15 06:24 2026-05-15 Show GitHub Exploit DB Packet Storm
1425 8.3 HIGH
Network
- - SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML wit… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-44586 2026-05-15 06:22 2026-05-15 Show GitHub Exploit DB Packet Storm
1426 4.3 MEDIUM
Network
- - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly… CWE-285
CWE-862
Improper Authorization
 Missing Authorization
CVE-2026-45147 2026-05-15 06:22 2026-05-15 Show GitHub Exploit DB Packet Storm
1427 6.5 MEDIUM
Network
hcltech bigfix_webui_api
bigfix_webui_application_administration
bigfix_webui_cmep
bigfix_webui_common
bigfix_webui_content_app
bigfix_webui_custom
bigfix_webui_data_sync
bigfix_webui_ex…
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)… CWE-863
 Incorrect Authorization
CVE-2025-15633 2026-05-15 05:28 2026-05-9 Show GitHub Exploit DB Packet Storm
1428 4.3 MEDIUM
Network
hcltech bigfix_webui_api
bigfix_webui_application_administration
bigfix_webui_cmep
bigfix_webui_common
bigfix_webui_content_app
bigfix_webui_custom
bigfix_webui_data_sync
bigfix_webui_ex…
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized… CWE-862
 Missing Authorization
CVE-2025-15634 2026-05-15 05:28 2026-05-9 Show GitHub Exploit DB Packet Storm
1429 7.8 HIGH
Local
python pillow Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e… CWE-190
CWE-787
 Integer Overflow or Wraparound
 Out-of-bounds Write
CVE-2026-42311 2026-05-15 05:27 2026-05-9 Show GitHub Exploit DB Packet Storm
1430 7.6 HIGH
Network
- - Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted… CWE-22
Path Traversal
CVE-2026-45225 2026-05-15 05:17 2026-05-13 Show GitHub Exploit DB Packet Storm