Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1241 6.1 警告
Network
Razorpay Razorpay Payment Button Plugin Razorpay の WordPress 用 Razorpay Payment Button Plugin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-10851 2025-01-20 15:42 2024-11-13 Show GitHub Exploit DB Packet Storm
1242 9.8 緊急
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3315 2025-01-20 15:27 2024-04-4 Show GitHub Exploit DB Packet Storm
1243 6.1 警告
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3377 2025-01-20 15:27 2024-04-6 Show GitHub Exploit DB Packet Storm
1244 5.4 警告
Network
Argie Online courseware Argie の Online courseware におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3426 2025-01-20 15:27 2024-04-7 Show GitHub Exploit DB Packet Storm
1245 8.8 重要
Network
Ivanti connect secure Ivanti の connect secure における脆弱性 CWE-602
CWE-Other
CVE-2024-9844 2025-01-20 15:27 2024-12-10 Show GitHub Exploit DB Packet Storm
1246 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows Server 2022
Microsoft Windows Server 2012
Microsoft Window…
Windows CSC Service Elevation of Privilege Vulnerability CWE-122
CWE-noinfo
CVE-2025-21378 2025-01-20 15:26 2025-01-14 Show GitHub Exploit DB Packet Storm
1247 4.3 警告
Network
WebTechStreet Elementor Addon Elements WebTechStreet の WordPress 用 Elementor Addon Elements における脆弱性 CWE-200
CWE-noinfo
CVE-2024-8902 2025-01-20 15:16 2024-10-12 Show GitHub Exploit DB Packet Storm
1248 8.8 重要
Network
SimpleHelp Ltd SimpleHelp SimpleHelp Ltd の SimpleHelp における脆弱性 CWE-noinfo
情報不足
CVE-2024-57726 2025-01-20 15:16 2025-01-15 Show GitHub Exploit DB Packet Storm
1249 9.8 緊急
Network
Progress Software Corporation MOVEit Transfer Progress Software Corporation の MOVEit Transfer における脆弱性 CWE-287
CWE-noinfo
CVE-2024-5806 2025-01-20 15:16 2024-06-25 Show GitHub Exploit DB Packet Storm
1250 7.5 重要
Network
Couchbase, Inc. couchbase server Couchbase, Inc. の Couchbase Server における脆弱性 CWE-200
CWE-noinfo
CVE-2024-23302 2025-01-20 15:15 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 4, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
171 7.8 HIGH
Local
apple watchos
ipados
macos
tvos
iphone_os
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory. Update CWE-787
 Out-of-bounds Write
CVE-2024-54517 2025-02-1 06:15 2025-01-28 Show GitHub Exploit DB Packet Storm
172 7.2 HIGH
Network
vruiz vr-frases The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 due to insufficient escaping on the user … Update CWE-89
SQL Injection
CVE-2025-0861 2025-02-1 05:43 2025-01-30 Show GitHub Exploit DB Packet Storm
173 6.1 MEDIUM
Network
vruiz vr-frases The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in all versions up to, and including, 3.0.1 due to insufficient inpu… Update CWE-79
Cross-site Scripting
CVE-2025-0860 2025-02-1 05:42 2025-01-30 Show GitHub Exploit DB Packet Storm
174 6.5 MEDIUM
Network
dwbooster cp_contact_form The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on … Update CWE-352
 Origin Validation Error
CVE-2024-13758 2025-02-1 05:28 2025-01-30 Show GitHub Exploit DB Packet Storm
175 5.4 MEDIUM
Network
cyberchimps responsive_blocks The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to… Update CWE-79
Cross-site Scripting
CVE-2024-13732 2025-02-1 05:22 2025-01-30 Show GitHub Exploit DB Packet Storm
176 6.3 MEDIUM
Network
- - A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. This affects an unknown part of the file /parse/_call_job_search_ajax.php. The manipulation of t… New CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0934 2025-02-1 05:15 2025-02-1 Show GitHub Exploit DB Packet Storm
177 - - - The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only mean… New - CVE-2025-0938 2025-02-1 05:15 2025-02-1 Show GitHub Exploit DB Packet Storm
178 - - - In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace dumps a variable-sized sockaddr to userspace. There, the full sockaddr is copied… Update - CVE-2025-0662 2025-02-1 05:15 2025-01-30 Show GitHub Exploit DB Packet Storm
179 - - - A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4. Update - CVE-2024-57513 2025-02-1 05:15 2025-01-30 Show GitHub Exploit DB Packet Storm
180 4.3 MEDIUM
Network
visualmodo borderless The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zi… Update CWE-862
 Missing Authorization
CVE-2024-11583 2025-02-1 05:03 2025-01-30 Show GitHub Exploit DB Packet Storm