Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1271 6.7 警告
Local
フォーティネット FortiAnalyzer-BigData
FortiAnalyzer
FortiManager
複数のフォーティネット製品における OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2024-32118 2025-01-20 14:53 2024-11-12 Show GitHub Exploit DB Packet Storm
1272 6.7 警告
Local
フォーティネット FortiManager フォーティネットの FortiManager におけるコードインジェクションの脆弱性 CWE-1336
CWE-94
CVE-2023-47542 2025-01-20 14:50 2023-11-6 Show GitHub Exploit DB Packet Storm
1273 8.8 重要
Network
マイクロソフト Microsoft SQL Server SQL Server Native Client OLE DB プロバイダーのリモート コード実行に対する脆弱性 CWE-122
CWE-noinfo
CVE-2024-21425 2025-01-20 14:46 2024-07-9 Show GitHub Exploit DB Packet Storm
1274 8.8 重要
Network
マイクロソフト Microsoft SQL Server SQL Server Native Client OLE DB プロバイダーのリモート コード実行に対する脆弱性 CWE-122
CWE-noinfo
CVE-2024-21331 2025-01-20 14:38 2024-07-9 Show GitHub Exploit DB Packet Storm
1275 8.8 重要
Network
マイクロソフト Microsoft SQL Server SQL Server Native Client OLE DB プロバイダーのリモート コード実行に対する脆弱性 CWE-122
CWE-noinfo
CVE-2024-21317 2025-01-20 14:24 2024-07-9 Show GitHub Exploit DB Packet Storm
1276 8.8 重要
Network
Wpmet ElementsKit Elementor addons Wpmet の WordPress 用 ElementsKit Elementor addons における脆弱性 CWE-Other
その他
CVE-2024-2047 2025-01-20 14:10 2024-03-30 Show GitHub Exploit DB Packet Storm
1277 6.1 警告
Network
Rock Lobster Contact Form 7 Rock Lobster の WordPress 用 Contact Form 7 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2242 2025-01-20 14:10 2024-03-13 Show GitHub Exploit DB Packet Storm
1278 5.4 警告
Network
Livemesh Livemesh Addons for Elementor Livemesh の WordPress 用 Livemesh Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2655 2025-01-20 14:10 2024-04-10 Show GitHub Exploit DB Packet Storm
1279 5.4 警告
Network
Wpmet ElementsKit Elementor addons Wpmet の WordPress 用 ElementsKit Elementor addons におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2803 2025-01-20 14:09 2024-04-4 Show GitHub Exploit DB Packet Storm
1280 8.8 重要
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3316 2025-01-20 14:09 2024-04-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 9, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 3.9 LOW
Physics
google android In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor ha… CWE-125
Out-of-bounds Read
CVE-2025-20643 2025-02-5 00:19 2025-02-3 Show GitHub Exploit DB Packet Storm
532 - - - Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0… CWE-94
Code Injection
CVE-2025-24677 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
533 - - - Incorrect Privilege Assignment vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.1. CWE-266
 Incorrect Privilege Assignment
CVE-2025-24648 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
534 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check allows Reflected XSS. This issue affects WP24 Domain Check: from n/a throu… CWE-79
Cross-site Scripting
CVE-2025-24602 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
535 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.… CWE-79
Cross-site Scripting
CVE-2025-24599 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
536 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.… CWE-79
Cross-site Scripting
CVE-2025-24598 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
537 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs allows Reflected XSS. This issue affects Find Content IDs: fr… CWE-79
Cross-site Scripting
CVE-2025-23645 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
538 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Landoweb Programador World Cup Predictor allows Reflected XSS. This issue affects World Cup Predi… CWE-79
Cross-site Scripting
CVE-2025-22794 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
539 - - - Missing Authorization vulnerability in Ksher Ksher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ksher: from n/a through 1.1.2. CWE-862
 Missing Authorization
CVE-2025-22730 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm
540 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Traveler Code. This issue affects Traveler Code: from n/a through 3.1.0. CWE-89
SQL Injection
CVE-2025-22700 2025-02-5 00:15 2025-02-5 Show GitHub Exploit DB Packet Storm