Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4311 8.1 重要
Network
Monospace Inc Directus Monospace IncのDirectusにおける複数の脆弱性 CWE-200
CWE-863
CVE-2026-35442 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4312 9.1 緊急
Network
pyLoad-ng project pyLoad-ng pyLoad-ng projectのpyLoad-ngにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35459 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4313 9.9 緊急
Network
inventree project inventree inventree projectのinventreeにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2026-35477 2026-04-21 10:46 2026-04-8 Show GitHub Exploit DB Packet Storm
4314 8.1 重要
Network
inventree project inventree inventree projectのinventreeにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-35478 2026-04-21 10:45 2026-04-8 Show GitHub Exploit DB Packet Storm
4315 7.5 重要
Network
liquidjs liquidjs liquidjsにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-39412 2026-04-21 10:45 2026-04-8 Show GitHub Exploit DB Packet Storm
4316 5.5 警告
Network
MaxKB MaxKB MaxKBにおける複数の脆弱性 CWE-20
CWE-78
CVE-2026-39417 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4317 7.4 重要
Network
MaxKB MaxKB MaxKBにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-39418 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4318 3.1
Network
MaxKB MaxKB MaxKBにおける複数の脆弱性 CWE-290
CWE-693
CWE-74
CVE-2026-39419 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4319 7.4 重要
Network
MaxKB MaxKB MaxKBにおける複数の脆弱性 CWE-693
CWE-78
CVE-2026-39420 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
4320 7.4 重要
Network
MaxKB MaxKB MaxKBにおける複数の脆弱性 CWE-693
CWE-94
CVE-2026-39421 2026-04-21 10:45 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 7.5 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name pr… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45398 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
122 8.5 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only valida… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-45401 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
123 8.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file to … New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-45402 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
124 8.8 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter … New CWE-863
 Incorrect Authorization
CVE-2026-45672 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
125 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload c… New CWE-79
Cross-site Scripting
CVE-2026-44549 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
126 8.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTT… New CWE-22
Path Traversal
CVE-2026-44565 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
127 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original… New CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-44566 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
128 7.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of us… New CWE-602
CWE-863
 Client-Side Enforcement of Server-Side Security
 Incorrect Authorization
CVE-2026-44567 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
129 7.1 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels message management system that allows authenticated… New CWE-862
 Missing Authorization
CVE-2026-44569 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm
130 8.3 HIGH
Network
- - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surrounding the memories API were inconsistent, resulting in… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-44570 2026-05-19 02:36 2026-05-16 Show GitHub Exploit DB Packet Storm