Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2321 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45349 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2322 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-45350 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2323 6.5 警告
Network
openwebui open webui openwebuiのopen webuiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-45351 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2324 5.4 警告
Network
openwebui open webui openwebuiのopen webuiにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-45365 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2325 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45385 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2326 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45386 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2327 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-45387 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2328 7.2 重要
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-269
CWE-862
CVE-2026-45395 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2329 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-45399 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
2330 8.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45402 2026-05-20 13:25 2026-05-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346211 - zentracking zen_time_tracking Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) p… CWE-89
SQL Injection
CVE-2010-1053 2017-08-17 10:32 2010-03-23 Show GitHub Exploit DB Packet Storm
346212 - tufat osdate Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code v… CWE-94
Code Injection
CVE-2010-1055 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346213 - rockettheme com_rokdownloads Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in … CWE-22
Path Traversal
CVE-2010-1056 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346214 - phpkobo adfreely Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via… CWE-22
Path Traversal
CVE-2010-1057 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346215 - phpkobo address_book_script Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local … CWE-22
Path Traversal
CVE-2010-1058 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346216 - aspindir erolife_ajxgaleri_vt Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1064 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346217 - lebisoft ziyaretci_defteri Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1065 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346218 - the-ghost ar_web_content_manager AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for contr… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1066 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346219 - hasmir_alic e-membres E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1067 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm
346220 - netwin surgeftp Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid param… CWE-79
Cross-site Scripting
CVE-2010-1068 2017-08-17 10:32 2010-03-24 Show GitHub Exploit DB Packet Storm