Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1231 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における脆弱性 CWE-noinfo
情報不足
CVE-2023-52559 2025-01-20 16:39 2023-09-25 Show GitHub Exploit DB Packet Storm
1232 9.8 緊急
Network
Argie Online courseware Argie の Online Courseware における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3419 2025-01-20 16:32 2024-04-7 Show GitHub Exploit DB Packet Storm
1233 5.3 警告
Network
RadiusTheme classified listing - classified ads & business directory RadiusTheme の WordPress 用 classified listing - classified ads & business directory における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1352 2025-01-20 16:24 2024-04-9 Show GitHub Exploit DB Packet Storm
1234 8.8 重要
Network
illumio core policy compute engine Illumio の Illumio Core Policy Compute Engine における信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2023-5183 2025-01-20 16:24 2023-09-27 Show GitHub Exploit DB Packet Storm
1235 6.5 警告
Network
Hire Web Xperts Passwords Manager Hire Web Xperts の WordPress 用 Passwords Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-12615 2025-01-20 16:17 2024-12-13 Show GitHub Exploit DB Packet Storm
1236 4.3 警告
Network
zixn Buy one click WooCommerce zixn の WordPress 用 Buy one click WooCommerce における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-10854 2025-01-20 16:06 2024-11-13 Show GitHub Exploit DB Packet Storm
1237 6.1 警告
Network
WP Brutal AI project WP Brutal AI WP Brutal AI project の WordPress 用 WP Brutal AI における脆弱性 - CVE-2023-2605 2025-01-20 16:03 2023-06-27 Show GitHub Exploit DB Packet Storm
1238 7.8 重要
Local
Huawei curiem-wfg9b ファームウェア Huawei の CurieM-WFG9B ファームウェアにおける境界外書き込みに関する脆弱性 CWE-130
CWE-787
CVE-2023-52547 2025-01-20 16:03 2024-05-28 Show GitHub Exploit DB Packet Storm
1239 7.3 重要
Network
awesomesupport awesome support wordpress helpdesk & support Awesome Support Team の WordPress 用 Awesome Support - WordPress HelpDesk & Support Plugin における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2023-51537 2025-01-20 15:54 2023-12-20 Show GitHub Exploit DB Packet Storm
1240 5.4 警告
Network
kaliforms Contact Form builder with drag & drop for WordPress - Kali Forms kaliforms の WordPress 用 Contact Form builder with drag & drop for WordPress - Kali Forms における脆弱性 CWE-noinfo
情報不足
CVE-2024-1218 2025-01-20 15:49 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 4, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
277871 - ntfs-3g ntfs-3g The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group … CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-5159 2008-09-6 06:30 2007-10-1 Show GitHub Exploit DB Packet Storm
277872 - restaurant_management_system restaurant_management_system Multiple PHP remote file inclusion vulnerabilities in Thierry Leriche Restaurant Management System (ReMaSys) 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the DIR_ROOT par… CWE-94
Code Injection
CVE-2007-5160 2008-09-6 06:30 2007-10-1 Show GitHub Exploit DB Packet Storm
277873 - phplister phplister PHP remote file inclusion vulnerability in .systeme/fonctions.php in phpLister 0.5-pre2 allows remote attackers to execute arbitrary PHP code via a URL in the nom_rep_systeme parameter. CWE-94
Code Injection
CVE-2007-5167 2008-09-6 06:30 2007-10-1 Show GitHub Exploit DB Packet Storm
277874 - y\&k_iletisim_formu y\&k_iletisim_formu Multiple cross-site scripting (XSS) vulnerabilities in iletisim.asp in Y&K Iletisim Formu allow remote attackers to inject arbitrary web script or HTML via the (1) ad, (2) sehir, (3) yas, (4) cins, (… CWE-79
Cross-site Scripting
CVE-2007-5179 2008-09-6 06:30 2007-10-3 Show GitHub Exploit DB Packet Storm
277875 - dircproxy dircproxy irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer derefere… CWE-20
 Improper Input Validation 
CVE-2007-5226 2008-09-6 06:30 2007-10-6 Show GitHub Exploit DB Packet Storm
277876 - activepdf server Heap-based buffer overflow in the activePDF Server service (aka APServer.exe) in activePDF Server 3.8.4 and 3.8.5.14, and possibly other versions before 3.8.6.16, allows remote attackers to execute a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5397 2008-09-6 06:30 2008-02-29 Show GitHub Exploit DB Packet Storm
277877 - claroline claroline Cross-site scripting (XSS) vulnerability in admin/adminusers.php in Claroline before 1.8.6 allows remote authenticated administrators to inject arbitrary web script or HTML via the sort parameter. N… CWE-79
Cross-site Scripting
CVE-2007-4741 2008-09-6 06:29 2007-09-7 Show GitHub Exploit DB Packet Storm
277878 - avnex av_mp3_player Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. NVD-CWE-noinfo
CVE-2007-4885 2008-09-6 06:29 2007-09-14 Show GitHub Exploit DB Packet Storm
277879 - netinvoicing netinvoicing Unspecified vulnerability in netInvoicing before 2.7.3 has unknown impact and attack vectors, related to "security check soap". NVD-CWE-noinfo
CVE-2007-4910 2008-09-6 06:29 2007-09-18 Show GitHub Exploit DB Packet Storm
277880 - invision_power_services invision_power_board ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where the… CWE-94
Code Injection
CVE-2007-4913 2008-09-6 06:29 2007-09-18 Show GitHub Exploit DB Packet Storm