Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190841 7.5 重要
Network
Sendio, Inc. - Sendio におけるファイルおよびディレクトリ情報の漏えいに関する脆弱性 CWE-538
ファイルおよびディレクトリ情報の漏えい
CVE-2016-10399 2017-09-1 13:50 2017-05-30 Show GitHub Exploit DB Packet Storm
190842 4.9 警告
Network
GLPI-PROJECT.ORG - GLPI における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2017-11183 2017-09-1 13:44 2017-07-13 Show GitHub Exploit DB Packet Storm
190843 5.5 警告
Local
Twibright Labs - Twibright Links における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2017-11114 2017-09-1 13:44 2017-07-30 Show GitHub Exploit DB Packet Storm
190844 7.5 重要
Network
Christian Schramm - shoco における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2017-11367 2017-09-1 12:30 2017-02-22 Show GitHub Exploit DB Packet Storm
190845 6.5 警告
Network
heinekingmedia GmbH - heinekingmedia StashCat における鍵管理のエラーに関する脆弱性 CWE-320
鍵管理のエラー
CVE-2017-11136 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
190846 7.5 重要
Network
heinekingmedia GmbH - heinekingmedia StashCat における認可に関する脆弱性 CWE-285
不適切な認可
CVE-2017-11135 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
190847 6.5 警告
Network
heinekingmedia GmbH - heinekingmedia StashCat における認可・権限・アクセス制御に関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-11134 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
190848 7.5 重要
Network
heinekingmedia GmbH - heinekingmedia StashCat における暗号アルゴリズムの使用に関する脆弱性 CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2017-11133 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
190849 7.5 重要
Network
heinekingmedia GmbH - heinekingmedia StashCat における暗号に関する脆弱性 CWE-310
暗号の問題
CVE-2017-11132 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
190850 5.9 警告
Network
heinekingmedia GmbH - heinekingmedia StashCat における暗号に関する脆弱性 CWE-310
暗号の問題
CVE-2017-11131 2017-09-1 11:46 2017-07-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
101 7.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forw… New CWE-284
CWE-862
Improper Access Control
 Missing Authorization
CVE-2026-44556 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
102 4.3 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _validate_collection_access function uses an incomplete allowlist that only enfo… New CWE-863
 Incorrect Authorization
CVE-2026-44557 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
103 6.5 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_impor… New CWE-283
CWE-862
 Unverified Ownership
 Missing Authorization
CVE-2026-44562 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
104 5.4 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any m… New CWE-862
 Missing Authorization
CVE-2026-44563 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
105 5.4 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a memb… New CWE-863
 Incorrect Authorization
CVE-2026-44564 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
106 4.8 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overl… New CWE-79
Cross-site Scripting
CVE-2026-44568 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
107 6.5 MEDIUM
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When… New CWE-863
 Incorrect Authorization
CVE-2026-45339 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
108 7.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API endpoint: /api/chat/completions with their own API … New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45349 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
109 8.5 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45331 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
110 7.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks acr… New CWE-862
 Missing Authorization
CVE-2026-45399 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm