Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4211 7.3 重要
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-44721 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
4212 5.5 警告
Local
Vim Vim Vimにおける複数の脆弱性 CWE-122
CWE-190
CVE-2026-45130 2026-05-20 13:27 2026-05-8 Show GitHub Exploit DB Packet Storm
4213 5.4 警告
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45299 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
4214 8.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-45301 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
4215 7.7 重要
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45303 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
4216 6.1 警告
Network
openwebui open webui openwebuiのopen webuiにおける代替 XSS 構文の不適切な無効化に関する脆弱性 CWE-87
代替 XSS 構文の不適切な無効化
CVE-2026-45314 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
4217 8.7 重要
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-434
CWE-646
CWE-79
CVE-2026-45315 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
4218 3.5
Network
openwebui open webui openwebuiのopen webuiにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-45316 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
4219 4.6 警告
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-20
CWE-352
CVE-2026-45317 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
4220 5.4 警告
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45318 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 25, 2026, 4:04 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315471 - - - Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows att… - CVE-2024-48176 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315472 - - - An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location … - CVE-2024-47464 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315473 - - - An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to c… - CVE-2024-47463 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315474 - - - An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to c… - CVE-2024-47462 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315475 - - - An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbit… - CVE-2024-47461 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315476 - - - Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point manag… - CVE-2024-47460 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315477 - - - Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point manag… - CVE-2024-42509 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315478 - - - Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'. - CVE-2024-51116 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315479 4.3 MEDIUM
Network
- - The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes… CWE-200
Information Exposure
CVE-2024-10084 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm
315480 - - - A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploita… - CVE-2024-7995 2024-11-7 03:17 2024-11-6 Show GitHub Exploit DB Packet Storm