Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4251 7.5 重要
Network
goxmldsig project goxmldsig goxmldsig projectのgoxmldsigにおける複数の脆弱性 CWE-347
CWE-682
CVE-2026-33487 2026-04-21 10:48 2026-03-26 Show GitHub Exploit DB Packet Storm
4252 8.7 重要
Local
Craig J. Bass (craigjbass) ClearanceKit Craig J. Bass (craigjbass)のClearanceKitにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33631 2026-04-21 10:48 2026-03-26 Show GitHub Exploit DB Packet Storm
4253 7.5 重要
Network
Moby Project buildkit Moby Projectのbuildkitにおける複数の脆弱性 CWE-22
CWE-59
CVE-2026-33748 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
4254 8.8 重要
Network
Intermesh Group-Office Intermesh BVのGroup-OfficeにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-33755 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
4255 7.5 重要
Network
saleor saleor saleorにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-33756 2026-04-21 10:48 2026-04-8 Show GitHub Exploit DB Packet Storm
4256 3.7
Network
Apostrophe Technologies ApostropheCMS Apostrophe TechnologiesのApostropheCMSにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-33877 2026-04-21 10:48 2026-04-15 Show GitHub Exploit DB Packet Storm
4257 5.3 警告
Network
Apostrophe Technologies ApostropheCMS Apostrophe TechnologiesのApostropheCMSにおける複数の脆弱性 CWE-200
CWE-863
CVE-2026-33888 2026-04-21 10:48 2026-04-15 Show GitHub Exploit DB Packet Storm
4258 5.4 警告
Network
Apostrophe Technologies ApostropheCMS Apostrophe TechnologiesのApostropheCMSにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33889 2026-04-21 10:48 2026-04-15 Show GitHub Exploit DB Packet Storm
4259 6.5 警告
Adjacent
Ellanetworks Ella Core EllanetworksのElla CoreにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2026-33903 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
4260 6.5 警告
Adjacent
Ellanetworks Ella Core EllanetworksのElla Coreにおけるデッドロックに関する脆弱性 CWE-833
デッドロック
CVE-2026-33904 2026-04-21 10:48 2026-03-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 7.5 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name pr… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45398 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
122 8.5 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only valida… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45401 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
123 8.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file to … New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45402 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
124 8.8 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter … New CWE-863
 Incorrect Authorization
CVE-2026-45672 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
125 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload c… New CWE-79
Cross-site Scripting
CVE-2026-44549 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
126 8.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTT… New CWE-22
Path Traversal
CVE-2026-44565 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
127 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original… New CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-44566 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
128 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of us… New CWE-602
CWE-863
 Client-Side Enforcement of Server-Side Security
 Incorrect Authorization
CVE-2026-44567 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
129 7.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels message management system that allows authenticated… New CWE-862
 Missing Authorization
CVE-2026-44569 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
130 8.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surrounding the memories API were inconsistent, resulting in… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-44570 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm