Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1231 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における脆弱性 CWE-noinfo
情報不足
CVE-2023-52559 2025-01-20 16:39 2023-09-25 Show GitHub Exploit DB Packet Storm
1232 9.8 緊急
Network
Argie Online courseware Argie の Online Courseware における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3419 2025-01-20 16:32 2024-04-7 Show GitHub Exploit DB Packet Storm
1233 5.3 警告
Network
RadiusTheme classified listing - classified ads & business directory RadiusTheme の WordPress 用 classified listing - classified ads & business directory における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1352 2025-01-20 16:24 2024-04-9 Show GitHub Exploit DB Packet Storm
1234 8.8 重要
Network
illumio core policy compute engine Illumio の Illumio Core Policy Compute Engine における信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2023-5183 2025-01-20 16:24 2023-09-27 Show GitHub Exploit DB Packet Storm
1235 6.5 警告
Network
Hire Web Xperts Passwords Manager Hire Web Xperts の WordPress 用 Passwords Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-12615 2025-01-20 16:17 2024-12-13 Show GitHub Exploit DB Packet Storm
1236 4.3 警告
Network
zixn Buy one click WooCommerce zixn の WordPress 用 Buy one click WooCommerce における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-10854 2025-01-20 16:06 2024-11-13 Show GitHub Exploit DB Packet Storm
1237 6.1 警告
Network
WP Brutal AI project WP Brutal AI WP Brutal AI project の WordPress 用 WP Brutal AI における脆弱性 - CVE-2023-2605 2025-01-20 16:03 2023-06-27 Show GitHub Exploit DB Packet Storm
1238 7.8 重要
Local
Huawei curiem-wfg9b ファームウェア Huawei の CurieM-WFG9B ファームウェアにおける境界外書き込みに関する脆弱性 CWE-130
CWE-787
CVE-2023-52547 2025-01-20 16:03 2024-05-28 Show GitHub Exploit DB Packet Storm
1239 7.3 重要
Network
awesomesupport awesome support wordpress helpdesk & support Awesome Support Team の WordPress 用 Awesome Support - WordPress HelpDesk & Support Plugin における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2023-51537 2025-01-20 15:54 2023-12-20 Show GitHub Exploit DB Packet Storm
1240 5.4 警告
Network
kaliforms Contact Form builder with drag & drop for WordPress - Kali Forms kaliforms の WordPress 用 Contact Form builder with drag & drop for WordPress - Kali Forms における脆弱性 CWE-noinfo
情報不足
CVE-2024-1218 2025-01-20 15:49 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 19, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1081 - - - NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phish… CWE-79
Cross-site Scripting
CVE-2025-1145 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1082 - - - School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrat… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-1144 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1083 - - - Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of th… CWE-798
 Use of Hard-coded Credentials
CVE-2025-1143 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1084 - - - A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/Category.php. The manipulation… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-1170 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1085 3.5 LOW
Network
- - A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The m… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-1169 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1086 - - - A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php.… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1168 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1087 - - - A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1167 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1088 - - - A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The mani… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-1166 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1089 - - - SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any… CWE-22
Path Traversal
CVE-2025-25243 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1090 - - - Due to a missing authorization check, an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads to … CWE-862
 Missing Authorization
CVE-2025-25241 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm