Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1001 5.4 警告
Network
bdthemes element pack bdthemes の WordPress 用 element pack におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-32572 2025-01-22 16:35 2024-04-18 Show GitHub Exploit DB Packet Storm
1002 5.4 警告
Network
webangon the pack elementor addons webangon の WordPress 用 the pack elementor addons におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2024-32718 2025-01-22 16:35 2024-04-24 Show GitHub Exploit DB Packet Storm
1003 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-32791 2025-01-22 16:35 2024-04-24 Show GitHub Exploit DB Packet Storm
1004 5.4 警告
Network
TYPO3 Association TYPO3 TYPO3 Association の TYPO3 におけるクロスサイトスクリプティングの脆弱性 CWE-116
CWE-79
CWE-79
CVE-2024-34355 2025-01-22 16:35 2024-05-14 Show GitHub Exploit DB Packet Storm
1005 7.5 重要
Network
BlackBerry QNX Software Development Platform BlackBerry の QNX Software Development Platform における境界外読み取りに関する脆弱性 CWE-125
CWE-125
CVE-2024-48855 2025-01-22 16:35 2024-10-8 Show GitHub Exploit DB Packet Storm
1006 7.5 重要
Network
bdthemes element pack bdthemes の WordPress 用 element pack における脆弱性 CWE-noinfo
情報不足
CVE-2024-2966 2025-01-22 16:27 2024-04-11 Show GitHub Exploit DB Packet Storm
1007 7.8 重要
Local
デル repository manager デルの repository manager におけるパストラバーサルの脆弱性 CWE-20
CWE-22
CVE-2024-28976 2025-01-22 16:26 2024-04-24 Show GitHub Exploit DB Packet Storm
1008 7.1 重要
Local
sixlabors imagesharp sixlabors の imagesharp における解放済みメモリの使用に関する脆弱性 CWE-416
CWE-416
CVE-2024-27929 2025-01-22 16:24 2024-03-5 Show GitHub Exploit DB Packet Storm
1009 5.4 警告
Network
exclusiveaddons exclusive addons for elementor exclusiveaddons の WordPress 用 exclusive addons for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2751 2025-01-22 16:22 2024-05-2 Show GitHub Exploit DB Packet Storm
1010 8.1 重要
Network
WonderCMS WonderCMS WonderCMS におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
CWE-918
CVE-2024-27561 2025-01-22 16:22 2024-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 3, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
277731 - liferay liferay_enterprise_portal Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated… CWE-352
 Origin Validation Error
CVE-2008-0182 2008-09-6 06:34 2008-02-5 Show GitHub Exploit DB Packet Storm
277732 - ngircd ngircd ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference. NVD-CWE-Other
CVE-2008-0285 2008-09-6 06:34 2008-01-16 Show GitHub Exploit DB Packet Storm
277733 - pmachine pmachine_pro Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter. CWE-79
Cross-site Scripting
CVE-2008-0334 2008-09-6 06:34 2008-01-18 Show GitHub Exploit DB Packet Storm
277734 - mahara mahara Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files. CWE-79
Cross-site Scripting
CVE-2008-0381 2008-09-6 06:34 2008-01-23 Show GitHub Exploit DB Packet Storm
277735 - bcoos event_calendar Cross-site scripting (XSS) vulnerability in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 allows remote attackers to inject arbitrary web script or HTML via the month parameter. NOT… CWE-79
Cross-site Scripting
CVE-2007-6365 2008-09-6 06:33 2007-12-15 Show GitHub Exploit DB Packet Storm
277736 - e-xoops e-xoops Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.p… CWE-89
SQL Injection
CVE-2007-6380 2008-09-6 06:33 2007-12-15 Show GitHub Exploit DB Packet Storm
277737 - serendipity serendipity Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to condu… CWE-352
 Origin Validation Error
CVE-2007-6390 2008-09-6 06:33 2007-12-18 Show GitHub Exploit DB Packet Storm
277738 - debian debian_linux scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options. CWE-94
Code Injection
CVE-2007-6415 2008-09-6 06:33 2008-01-25 Show GitHub Exploit DB Packet Storm
277739 - anon_proxy_server anon_proxy_server Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.ph… CWE-79
Cross-site Scripting
CVE-2007-6460 2008-09-6 06:33 2007-12-20 Show GitHub Exploit DB Packet Storm
277740 - phprpg phprpg SQL injection vulnerability in index.php in phpRPG 0.8, when magic_qutoes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these d… CWE-89
SQL Injection
CVE-2007-6469 2008-09-6 06:33 2007-12-20 Show GitHub Exploit DB Packet Storm