Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1081 5.4 警告
Network
POSIMYTH The Plus Addons for Elementor Page Builder POSIMYTH の WordPress 用 The Plus Addons for Elementor Page Builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3197 2025-01-22 10:35 2024-05-2 Show GitHub Exploit DB Packet Storm
1082 8.8 重要
Network
XWiki xwiki XWiki の xwiki における認証の欠如に関する脆弱性 CWE-862
CWE-862
CVE-2024-31983 2025-01-22 10:35 2024-04-10 Show GitHub Exploit DB Packet Storm
1083 6.1 警告
Network
PrestaShop PrestaShop PrestaShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-34716 2025-01-22 10:35 2024-05-14 Show GitHub Exploit DB Packet Storm
1084 9.8 緊急
Network
マイクロフォーカス株式会社 imanager マイクロフォーカス株式会社の imanager におけるコマンドインジェクションの脆弱性 CWE-434
CWE-502
CWE-502
CWE-77
CWE-77
CVE-2024-3483 2025-01-22 10:35 2024-05-15 Show GitHub Exploit DB Packet Storm
1085 9.8 緊急
Network
マイクロフォーカス株式会社 imanager マイクロフォーカス株式会社の imanager における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-20
CWE-434
CVE-2024-3488 2025-01-22 10:35 2024-05-15 Show GitHub Exploit DB Packet Storm
1086 5.4 警告
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3695 2025-01-22 10:35 2024-04-12 Show GitHub Exploit DB Packet Storm
1087 7.3 重要
Local
マイクロソフト Microsoft Visual Studio Visual Studio の特権の昇格の脆弱性 CWE-284
CWE-noinfo
CVE-2025-21405 2025-01-22 10:09 2025-01-14 Show GitHub Exploit DB Packet Storm
1088 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Access
Microsoft Access のリモート コードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21366 2025-01-22 10:06 2025-01-14 Show GitHub Exploit DB Packet Storm
1089 8.4 重要
Local
マイクロソフト Microsoft Office
Microsoft Office Online Server
Microsoft Excel
Microsoft 365 Apps
Microsoft Excel のリモートでコードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21362 2025-01-22 09:48 2025-01-14 Show GitHub Exploit DB Packet Storm
1090 7.8 重要
Local
マイクロソフト Microsoft AutoUpdate Microsoft AutoUpdate (MAU) の特権昇格の脆弱性 CWE-269
CWE-noinfo
CVE-2025-21360 2025-01-22 09:43 2025-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 1, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
280801 - netscape enterprise_server
fasttrack_server
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. NVD-CWE-Other
CVE-1999-0744 2008-09-6 05:17 2000-01-4 Show GitHub Exploit DB Packet Storm
280802 - oracle database_server Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP. NVD-CWE-Other
CVE-1999-0784 2008-09-6 05:17 2001-03-12 Show GitHub Exploit DB Packet Storm
280803 - freebsd freebsd TCP RST denial of service in FreeBSD. NVD-CWE-Other
CVE-1999-0053 2008-09-6 05:16 1998-10-13 Show GitHub Exploit DB Packet Storm
280804 - ssh ssh A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. NVD-CWE-Other
CVE-1999-0248 2008-09-6 05:16 1999-01-1 Show GitHub Exploit DB Packet Storm
280805 - freebsd freebsd Buffer overflow in FreeBSD lpd through long DNS hostnames. NVD-CWE-Other
CVE-1999-0299 2008-09-6 05:16 1997-03-5 Show GitHub Exploit DB Packet Storm
280806 - d-ic shop_v50
shop_v52
Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2008-3935 2008-09-6 00:08 2008-09-6 Show GitHub Exploit DB Packet Storm
280807 - opendb opendb Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an … CWE-79
Cross-site Scripting
CVE-2008-3937 2008-09-6 00:08 2008-09-6 Show GitHub Exploit DB Packet Storm
280808 - opendb opendb Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action. CWE-352
 Origin Validation Error
CVE-2008-3938 2008-09-6 00:08 2008-09-6 Show GitHub Exploit DB Packet Storm
280809 - avtech pager_enterprise Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI. CWE-22
Path Traversal
CVE-2008-3939 2008-09-6 00:08 2008-09-6 Show GitHub Exploit DB Packet Storm
280810 - manageengine servicedesk_plus Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the sear… CWE-79
Cross-site Scripting
CVE-2008-1299 2008-09-5 13:00 2008-03-13 Show GitHub Exploit DB Packet Storm