Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1151 7.8 重要
Local
マイクロソフト Microsoft Windows 10
Microsoft Windows Server 2019
Microsoft Windows Server 2025
Microsoft Windows 11
Microsoft Windows Server&…
Windows Graphics コンポーネントの特権の昇格の脆弱性 CWE-122
CWE-190
CWE-noinfo
CVE-2025-21382 2025-01-21 08:49 2025-01-14 Show GitHub Exploit DB Packet Storm
1152 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows Server 2012
Microsoft Windows 10
Microsoft Windows Server 2019
Microsoft Window…
Windows upnphost.dll のサービス拒否の脆弱性 CWE-400
CWE-noinfo
CVE-2025-21389 2025-01-21 08:49 2025-01-14 Show GitHub Exploit DB Packet Storm
1153 8.8 重要
Network
wpextended The Ultimate WordPress Toolkit  - WP Extended wpextended の WordPress 用 The Ultimate WordPress Toolkit - WP Extended における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-11816 2025-01-21 08:41 2024-11-26 Show GitHub Exploit DB Packet Storm
1154 5.4 警告
Network
Jenkins プロジェクト Build Monitor View Jenkins プロジェクトの Jenkins 用 Build Monitor View におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-28156 2025-01-21 08:41 2024-03-6 Show GitHub Exploit DB Packet Storm
1155 3.3
Local
Phiewer Phiewer Phiewer における信頼できない検索パスに関する脆弱性 CWE-426
信頼性のない検索パス
CVE-2024-53407 2025-01-21 08:37 2024-11-20 Show GitHub Exploit DB Packet Storm
1156 8.8 重要
Network
Ivanti connect secure Ivanti の connect secure における解放済みメモリの使用に関する脆弱性 CWE-416
CWE-416
CVE-2024-9420 2025-01-20 18:27 2024-11-12 Show GitHub Exploit DB Packet Storm
1157 7.1 重要
Local
Ivanti secure access client Ivanti の secure access client における脆弱性 CWE-267
CWE-Other
CVE-2024-8539 2025-01-20 18:26 2024-11-12 Show GitHub Exploit DB Packet Storm
1158 5.5 警告
Local
Huawei EMUI
HarmonyOS
Huawei の EMUI および HarmonyOS における脆弱性 CWE-20
CWE-noinfo
CVE-2024-54101 2025-01-20 18:25 2024-12-12 Show GitHub Exploit DB Packet Storm
1159 7.2 重要
Network
instantcms instantcms instantcms における SQL インジェクションの脆弱性 CWE-20
CWE-89
CWE-89
CVE-2024-31212 2025-01-20 18:24 2024-04-4 Show GitHub Exploit DB Packet Storm
1160 9.8 緊急
Network
StylemixThemes MasterStudy LMS StylemixThemes の WordPress 用 MasterStudy LMS における脆弱性 CWE-Other
その他
CVE-2024-3136 2025-01-20 18:24 2024-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 1, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
11 4.3 MEDIUM
Network
- - IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an obse… New CWE-203
 Information Exposure Through Discrepancy
CVE-2024-45089 2025-02-1 01:15 2025-02-1 Show GitHub Exploit DB Packet Storm
12 4.8 MEDIUM
Network
- - IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary … New CWE-79
Cross-site Scripting
CVE-2024-40696 2025-02-1 01:15 2025-02-1 Show GitHub Exploit DB Packet Storm
13 - - - Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixe… New - CVE-2024-11741 2025-02-1 01:15 2025-02-1 Show GitHub Exploit DB Packet Storm
14 4.3 MEDIUM
Network
- - IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… New CWE-352
 Origin Validation Error
CVE-2023-38739 2025-02-1 01:15 2025-02-1 Show GitHub Exploit DB Packet Storm
15 - - - Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. New CWE-428
 Unquoted Search Path or Element
CVE-2025-24831 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm
16 - - - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. New CWE-426
 Untrusted Search Path
CVE-2025-24830 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm
17 - - - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. New CWE-426
 Untrusted Search Path
CVE-2025-24829 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm
18 - - - The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and including, 2.4.1 due to… New CWE-79
Cross-site Scripting
CVE-2024-13662 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm
19 - - - The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an … New CWE-94
Code Injection
CVE-2024-12415 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm
20 5.3 MEDIUM
Network
- - The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_dele… New CWE-73
CWE-862
 External Control of File Name or Path
 Missing Authorization
CVE-2024-12267 2025-02-1 01:15 2025-01-31 Show GitHub Exploit DB Packet Storm