Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
631 8.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-45301 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
632 7.7 重要
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45303 2026-05-20 13:27 2026-05-15 Show GitHub Exploit DB Packet Storm
633 6.1 警告
Network
openwebui open webui openwebuiのopen webuiにおける代替 XSS 構文の不適切な無効化に関する脆弱性 CWE-87
代替 XSS 構文の不適切な無効化
CVE-2026-45314 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
634 8.7 重要
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-434
CWE-646
CWE-79
CVE-2026-45315 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
635 3.5
Network
openwebui open webui openwebuiのopen webuiにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-45316 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
636 4.6 警告
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-20
CWE-352
CVE-2026-45317 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
637 5.4 警告
Network
openwebui open webui openwebuiのopen webuiにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-45318 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
638 8.5 重要
Network
openwebui open webui openwebuiのopen webuiにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-45331 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
639 7.7 重要
Network
openwebui open webui openwebuiのopen webuiにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-45338 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
640 6.5 警告
Network
openwebui open webui openwebuiのopen webuiにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-45339 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345571 - sergey_kiselev sgallery SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters. NVD-CWE-Other
CVE-2005-0377 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345572 - horde horde Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.p… NVD-CWE-Other
CVE-2005-0378 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345573 - zeroboard zeroboard Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlog… NVD-CWE-Other
CVE-2005-0379 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345574 - zeroboard zeroboard Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attacke… NVD-CWE-Other
CVE-2005-0380 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345575 - forumkit forumkit Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter. NVD-CWE-Other
CVE-2005-0381 2017-07-11 10:32 2005-01-13 Show GitHub Exploit DB Packet Storm
345576 - breed breed Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference. NVD-CWE-Other
CVE-2005-0382 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345577 - trend_micro control_manager Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password. NVD-CWE-Other
CVE-2005-0383 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345578 - daniel_de_rauglaudre geneweb geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files. NVD-CWE-Other
CVE-2005-0391 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345579 - spidean postwrap Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter. NVD-CWE-Other
CVE-2005-0412 2017-07-11 10:32 2005-04-27 Show GitHub Exploit DB Packet Storm
345580 - mercuryboard mercuryboard SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu p… NVD-CWE-Other
CVE-2005-0414 2017-07-11 10:32 2005-04-27 Show GitHub Exploit DB Packet Storm