Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
871 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45349 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
872 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-45350 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
873 6.5 警告
Network
openwebui open webui openwebuiのopen webuiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-45351 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
874 5.4 警告
Network
openwebui open webui openwebuiのopen webuiにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-45365 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
875 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45385 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
876 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45386 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
877 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-45387 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
878 7.2 重要
Network
openwebui open webui openwebuiのopen webuiにおける複数の脆弱性 CWE-269
CWE-862
CVE-2026-45395 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
879 7.1 重要
Network
openwebui open webui openwebuiのopen webuiにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-45399 2026-05-20 13:26 2026-05-15 Show GitHub Exploit DB Packet Storm
880 8.1 重要
Network
openwebui open webui openwebuiのopen webuiにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-45402 2026-05-20 13:25 2026-05-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345571 - sergey_kiselev sgallery SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters. NVD-CWE-Other
CVE-2005-0377 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345572 - horde horde Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.p… NVD-CWE-Other
CVE-2005-0378 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345573 - zeroboard zeroboard Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlog… NVD-CWE-Other
CVE-2005-0379 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345574 - zeroboard zeroboard Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attacke… NVD-CWE-Other
CVE-2005-0380 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345575 - forumkit forumkit Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter. NVD-CWE-Other
CVE-2005-0381 2017-07-11 10:32 2005-01-13 Show GitHub Exploit DB Packet Storm
345576 - breed breed Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference. NVD-CWE-Other
CVE-2005-0382 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345577 - trend_micro control_manager Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password. NVD-CWE-Other
CVE-2005-0383 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345578 - daniel_de_rauglaudre geneweb geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files. NVD-CWE-Other
CVE-2005-0391 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
345579 - spidean postwrap Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter. NVD-CWE-Other
CVE-2005-0412 2017-07-11 10:32 2005-04-27 Show GitHub Exploit DB Packet Storm
345580 - mercuryboard mercuryboard SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu p… NVD-CWE-Other
CVE-2005-0414 2017-07-11 10:32 2005-04-27 Show GitHub Exploit DB Packet Storm