Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
206461 5.4 警告 Linux - Linux Kernel の net/unix/af_unix.c における AF_UNIX ソケットのパーミッションを回避される脆弱性 CWE-Other
その他
CVE-2013-7446 2016-01-5 11:12 2013-10-14 Show GitHub Exploit DB Packet Storm
206462 5 警告 IBM - IBM WebSphere Portal における Portal AccessControl REST API アクセス制限を回避される脆弱性 CWE-200
情報漏えい
CVE-2015-7447 2016-01-4 17:46 2015-12-15 Show GitHub Exploit DB Packet Storm
206463 6.9 警告 IBM - IBM InfoSphere BigInsights における権限を取得される脆弱性 CWE-Other
その他
CVE-2015-1947 2016-01-4 17:46 2015-12-17 Show GitHub Exploit DB Packet Storm
206464 7.5 危険 Epiphany Healthcare - Epiphany Cardio Server のログインページにおける LDAP インジェクション攻撃を実行される脆弱性 CWE-Other
その他
CVE-2015-6538 2016-01-4 17:33 2015-12-1 Show GitHub Exploit DB Packet Storm
206465 7.5 危険 Epiphany Healthcare - Epiphany Cardio Server のログインページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-6537 2016-01-4 17:33 2015-12-1 Show GitHub Exploit DB Packet Storm
206466 4.3 警告 RSI Video Technologies - RSI Video Technologies Videofied デバイス上で稼動する Frontel の独自プロトコルにおける偽の警報を発せられる脆弱性 CWE-Other
その他
CVE-2015-8254 2016-01-4 16:59 2015-11-30 Show GitHub Exploit DB Packet Storm
206467 4.3 警告 RSI Video Technologies - RSI Video Technologies Videofied デバイス上で稼動する Frontel の独自プロトコルにける重要なメッセージおよび MJPEG ビデオデータを取得される脆弱性 CWE-200
情報漏えい
CVE-2015-8253 2016-01-4 16:59 2015-11-30 Show GitHub Exploit DB Packet Storm
206468 4.3 警告 RSI Video Technologies - RSI Video Technologies Videofied デバイス上で稼動する Frontel の独自プロトコルにおけるハードコードされた鍵を特定される脆弱性 CWE-200
情報漏えい
CVE-2015-8252 2016-01-4 16:59 2015-11-30 Show GitHub Exploit DB Packet Storm
206469 6.8 警告 ZyXEL - ZyXEL NBG-418N デバイスのファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-7284 2016-01-4 16:52 2015-12-10 Show GitHub Exploit DB Packet Storm
206470 9.3 危険 ZyXEL - ZyXEL NBG-418N デバイスのファームウェアの Web 管理インターフェースにおける管理者権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2015-7283 2016-01-4 16:52 2015-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
561 7.1 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks acr… Update CWE-862
 Missing Authorization
CVE-2026-45399 2026-05-19 12:08 2026-05-16 Show GitHub Exploit DB Packet Storm
562 6.5 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When… Update CWE-863
 Incorrect Authorization
CVE-2026-45339 2026-05-19 12:07 2026-05-16 Show GitHub Exploit DB Packet Storm
563 8.5 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45331 2026-05-19 12:06 2026-05-16 Show GitHub Exploit DB Packet Storm
564 4.8 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overl… Update CWE-79
Cross-site Scripting
CVE-2026-44568 2026-05-19 12:06 2026-05-16 Show GitHub Exploit DB Packet Storm
565 4.3 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, when setting model permissions so that a group has read access to it, intending for … Update CWE-200
Information Exposure
CVE-2026-45387 2026-05-19 12:05 2026-05-16 Show GitHub Exploit DB Packet Storm
566 7.2 HIGH
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspac… Update CWE-269
CWE-862
 Improper Privilege Management
 Missing Authorization
CVE-2026-45395 2026-05-19 12:05 2026-05-16 Show GitHub Exploit DB Packet Storm
567 4.3 MEDIUM
Network
openwebui open_webui Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, an IDOR vulnerability exists in the Channels feature of Open WebUI, allowing any cha… Update CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45385 2026-05-19 10:45 2026-05-16 Show GitHub Exploit DB Packet Storm
568 6.3 MEDIUM
Network
open5gs open5gs A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in … Update CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-8743 2026-05-19 10:35 2026-05-17 Show GitHub Exploit DB Packet Storm
569 5.5 MEDIUM
Local
steipete summarize Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default… New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-45246 2026-05-19 10:34 2026-05-19 Show GitHub Exploit DB Packet Storm
570 5.4 MEDIUM
Network
steipete summarize Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu… New CWE-862
 Missing Authorization
CVE-2026-45244 2026-05-19 10:34 2026-05-19 Show GitHub Exploit DB Packet Storm