Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231651 4.3 警告 professional home page tools login script - Professional Home Page Tools Login Script におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-7078 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
231652 6.8 警告 phpBB - phpBB 用の Advanced Guestbook における SQL インジェクションの脆弱性 - CVE-2006-7077 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
231653 4.3 警告 phpBB - phpBB 用の Advanced Guestbook におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-7076 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
231654 7.5 危険 smartsitecms - SmartSiteCMS の admin.php における認証を回避される脆弱性 - CVE-2006-7074 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
231655 7.5 危険 socketwiz - Socketwiz Bookmarks の smarty_config.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-7069 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
231656 7.5 危険 tinyphpforum - TinyPHPforum の profile.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-7063 2012-12-20 18:18 2007-02-23 Show GitHub Exploit DB Packet Storm
231657 9.3 危険 scriptsez.net - Scriptsez.net E-Dating System におけるプライベートメッセージを読まれる脆弱性 - CVE-2006-7061 2012-12-20 18:18 2007-02-23 Show GitHub Exploit DB Packet Storm
231658 5.8 警告 サン・マイクロシステムズ - Sun Solaris の .iked などに使用されている libike ライブラリにおける PKCS #1 v1.5 署名を偽造される脆弱性 CWE-DesignError
CVE-2006-7140 2012-12-20 18:18 2006-11-27 Show GitHub Exploit DB Packet Storm
231659 5 警告 scriptsez.net - Scriptsez.net E-Dating System の cindex.php におけるフルパスを取得される脆弱性 - CVE-2006-7060 2012-12-20 18:18 2007-02-23 Show GitHub Exploit DB Packet Storm
231660 4.3 警告 scriptsez.net - Scriptsez.net E-Dating System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-7059 2012-12-20 18:18 2007-02-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
331 6.5 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context), type: "text" with collection_name, and bare col… Update CWE-862
 Missing Authorization
CVE-2026-44560 2026-05-19 12:09 2026-05-16 Show GitHub Exploit DB Packet Storm
332 4.3 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the GET /api/v1/channels/{id}/members endpoint only checks membership for group and … Update CWE-862
 Missing Authorization
CVE-2026-44559 2026-05-19 12:09 2026-05-16 Show GitHub Exploit DB Packet Storm
333 8.0 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE … Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45671 2026-05-19 12:08 2026-05-16 Show GitHub Exploit DB Packet Storm
334 7.1 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks acr… Update CWE-862
 Missing Authorization
CVE-2026-45399 2026-05-19 12:08 2026-05-16 Show GitHub Exploit DB Packet Storm
335 6.5 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When… Update CWE-863
 Incorrect Authorization
CVE-2026-45339 2026-05-19 12:07 2026-05-16 Show GitHub Exploit DB Packet Storm
336 8.5 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45331 2026-05-19 12:06 2026-05-16 Show GitHub Exploit DB Packet Storm
337 4.8 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overl… Update CWE-79
Cross-site Scripting
CVE-2026-44568 2026-05-19 12:06 2026-05-16 Show GitHub Exploit DB Packet Storm
338 4.3 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, when setting model permissions so that a group has read access to it, intending for … Update CWE-200
Information Exposure
CVE-2026-45387 2026-05-19 12:05 2026-05-16 Show GitHub Exploit DB Packet Storm
339 7.2 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspac… Update CWE-269
CWE-862
 Improper Privilege Management
 Missing Authorization
CVE-2026-45395 2026-05-19 12:05 2026-05-16 Show GitHub Exploit DB Packet Storm
340 4.3 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, an IDOR vulnerability exists in the Channels feature of Open WebUI, allowing any cha… Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45385 2026-05-19 10:45 2026-05-16 Show GitHub Exploit DB Packet Storm