Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1111 5.5 警告
Local
Linux
Debian
Linux Kernel
Debian GNU/Linux
Linux の Linux Kernel 等複数ベンダの製品におけるゼロ除算に関する脆弱性 CWE-369
ゼロ除算
CVE-2024-27059 2025-01-21 15:13 2024-03-2 Show GitHub Exploit DB Packet Storm
1112 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2022-48663 2025-01-21 15:09 2022-09-20 Show GitHub Exploit DB Packet Storm
1113 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2021-47199 2025-01-21 15:07 2021-11-16 Show GitHub Exploit DB Packet Storm
1114 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Access
Microsoft Access のリモート コードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21395 2025-01-21 14:52 2025-01-14 Show GitHub Exploit DB Packet Storm
1115 7.8 重要
Local
クアルコム WSA8830 ファームウェア
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
 BB) ファームウェア
sc8380xp ファームウェア
WCD9385 ファームウェア
fastconnect …
複数のクアルコム製品における脆弱性 CWE-284
CWE-Other
CVE-2024-23360 2025-01-21 14:42 2024-06-3 Show GitHub Exploit DB Packet Storm
1116 6.3 警告
Network
マイクロソフト Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Server のなりすましの脆弱性 CWE-79
CWE-noinfo
CVE-2025-21393 2025-01-21 14:30 2025-01-14 Show GitHub Exploit DB Packet Storm
1117 5.5 警告
Network
Alex Kirk Friends Alex Kirk の Friends におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2024-1978 2025-01-21 14:22 2024-02-29 Show GitHub Exploit DB Packet Storm
1118 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Office のリモート コードが実行される脆弱性 CWE-426
CWE-noinfo
CVE-2025-21365 2025-01-21 14:21 2025-01-14 Show GitHub Exploit DB Packet Storm
1119 4.3 警告
Network
Really Simple Plugins Complianz - GDPR/CCPA Cookie Consent Complianz の WordPress 用 Complianz - GDPR/CCPA Cookie Consent におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-1592 2025-01-21 14:18 2024-03-2 Show GitHub Exploit DB Packet Storm
1120 5 警告
Network
Outlook.com Microsoft Edge Chromium Microsoft Edge (Chrome ベース) のセキュリティ機能のバイパスの脆弱性 CWE-94
CWE-noinfo
CVE-2024-29991 2025-01-21 14:15 2024-04-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275111 - audiocoding faad2 Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2008-4201 2011-01-3 14:00 2008-09-24 Show GitHub Exploit DB Packet Storm
275112 - realnetworks helix_mobile_server
helix_server
helix_server_mobile
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers … CWE-189
Numeric Errors
CVE-2010-1319 2010-12-29 14:00 2010-04-21 Show GitHub Exploit DB Packet Storm
275113 - innovationdp fdr\/upstrean INNOVATION Data Processing FDR/UPSTREAM 3.3.0 (GA Oct 2003) allows remote attackers to cause a denial of service (service outage) via a sequence of TCP SYN packets to many ports, as demonstrated usin… NVD-CWE-Other
CVE-2006-6404 2010-12-29 14:00 2009-10-20 Show GitHub Exploit DB Packet Storm
275114 - sentex jhead jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. CWE-59
NVD-CWE-noinfo
Link Following
CVE-2008-4639 2010-12-28 14:00 2008-10-22 Show GitHub Exploit DB Packet Storm
275115 - mailscanner mailscanner mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) cla… CWE-59
Link Following
CVE-2008-5312 2010-12-28 14:00 2008-12-4 Show GitHub Exploit DB Packet Storm
275116 - mailscanner mailscanner mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clam… CWE-59
Link Following
CVE-2008-5313 2010-12-28 14:00 2008-12-4 Show GitHub Exploit DB Packet Storm
275117 - clixint image_hosting_script_dpi Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some … CWE-79
Cross-site Scripting
CVE-2009-4252 2010-12-22 14:00 2009-12-10 Show GitHub Exploit DB Packet Storm
275118 - gianluca_baldo phpauction Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (… CWE-79
Cross-site Scripting
CVE-2005-2254 2010-12-21 14:00 2005-07-13 Show GitHub Exploit DB Packet Storm
275119 - bsdi
freebsd
openbsd
bsd_os
freebsd
openbsd
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. CWE-20
 Improper Input Validation 
CVE-1999-0001 2010-12-16 14:00 1999-12-30 Show GitHub Exploit DB Packet Storm
275120 - 1024cms 1024_cms SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action. CWE-89
SQL Injection
CVE-2010-1093 2010-12-14 23:34 2010-03-25 Show GitHub Exploit DB Packet Storm