Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1081 5.4 警告
Network
POSIMYTH The Plus Addons for Elementor Page Builder POSIMYTH の WordPress 用 The Plus Addons for Elementor Page Builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3197 2025-01-22 10:35 2024-05-2 Show GitHub Exploit DB Packet Storm
1082 8.8 重要
Network
XWiki xwiki XWiki の xwiki における認証の欠如に関する脆弱性 CWE-862
CWE-862
CVE-2024-31983 2025-01-22 10:35 2024-04-10 Show GitHub Exploit DB Packet Storm
1083 6.1 警告
Network
PrestaShop PrestaShop PrestaShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-34716 2025-01-22 10:35 2024-05-14 Show GitHub Exploit DB Packet Storm
1084 9.8 緊急
Network
マイクロフォーカス株式会社 imanager マイクロフォーカス株式会社の imanager におけるコマンドインジェクションの脆弱性 CWE-434
CWE-502
CWE-502
CWE-77
CWE-77
CVE-2024-3483 2025-01-22 10:35 2024-05-15 Show GitHub Exploit DB Packet Storm
1085 9.8 緊急
Network
マイクロフォーカス株式会社 imanager マイクロフォーカス株式会社の imanager における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-20
CWE-434
CVE-2024-3488 2025-01-22 10:35 2024-05-15 Show GitHub Exploit DB Packet Storm
1086 5.4 警告
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3695 2025-01-22 10:35 2024-04-12 Show GitHub Exploit DB Packet Storm
1087 7.3 重要
Local
マイクロソフト Microsoft Visual Studio Visual Studio の特権の昇格の脆弱性 CWE-284
CWE-noinfo
CVE-2025-21405 2025-01-22 10:09 2025-01-14 Show GitHub Exploit DB Packet Storm
1088 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Access
Microsoft Access のリモート コードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21366 2025-01-22 10:06 2025-01-14 Show GitHub Exploit DB Packet Storm
1089 8.4 重要
Local
マイクロソフト Microsoft Office
Microsoft Office Online Server
Microsoft Excel
Microsoft 365 Apps
Microsoft Excel のリモートでコードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21362 2025-01-22 09:48 2025-01-14 Show GitHub Exploit DB Packet Storm
1090 7.8 重要
Local
マイクロソフト Microsoft AutoUpdate Microsoft AutoUpdate (MAU) の特権昇格の脆弱性 CWE-269
CWE-noinfo
CVE-2025-21360 2025-01-22 09:43 2025-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 1, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275711 - multi-website multi_website Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI. CWE-79
Cross-site Scripting
CVE-2009-3162 2009-09-11 13:00 2009-09-11 Show GitHub Exploit DB Packet Storm
275712 - openwebmail.acatysmoof openwebmail Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors. CWE-79
Cross-site Scripting
CVE-2008-7202 2009-09-11 13:00 2009-09-10 Show GitHub Exploit DB Packet Storm
275713 - allenthusiast reviewpost_php_pro Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter. CWE-79
Cross-site Scripting
CVE-2009-3147 2009-09-11 03:30 2009-09-11 Show GitHub Exploit DB Packet Storm
275714 - mark_reinsfelder metashell Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability. NVD-CWE-noinfo
CVE-2008-7196 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
275715 - g15tools g15daemon Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2008-7197 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
275716 - alecwh phpns Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2008-7198 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
275717 - phoenixcontact fl_il_24_bk-pac Phoenix Contact FL IL 24 BK-PAC allows remote attackers to cause a denial of service (hang) via (1) unspecified manipulations as demonstrated by a Nessus scan or (2) malformed input to TCP port 502. NVD-CWE-noinfo
CVE-2008-7199 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
275718 - deliantra deliantra Double free vulnerability in Deliantra server engine before 2.4 has unknown impact and attack vectors. NVD-CWE-Other
CVE-2008-7200 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
275719 - oxid eshop OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie. CWE-200
Information Exposure
CVE-2009-2266 2009-09-10 13:00 2009-09-10 Show GitHub Exploit DB Packet Storm
275720 - htmldoc htmldoc Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-3050 2009-09-10 13:00 2009-09-3 Show GitHub Exploit DB Packet Storm