Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1321 9.9 緊急
Network
Apache Software Foundation Apache Pulsar Apache Software Foundation の Apache Pulsar におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2024-27317 2025-01-20 11:52 2024-03-12 Show GitHub Exploit DB Packet Storm
1322 5.4 警告
Network
Contao contao Contao におけるインジェクションに関する脆弱性 CWE-74
CWE-74
CVE-2024-28191 2025-01-20 11:52 2024-04-9 Show GitHub Exploit DB Packet Storm
1323 7.1 重要
Local
Linux Linux Kernel Linux の Linux Kernel における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2021-47083 2025-01-20 11:51 2021-11-24 Show GitHub Exploit DB Packet Storm
1324 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2024-56629 2025-01-20 11:41 2024-11-28 Show GitHub Exploit DB Packet Storm
1325 7.1 重要
Local
Linux Linux Kernel Linux の Linux Kernel における境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2024-36931 2025-01-20 11:38 2024-04-29 Show GitHub Exploit DB Packet Storm
1326 8.8 重要
Network
マイクロソフト Microsoft OLE DB Driver
Microsoft SQL Server
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 CWE-191
CWE-noinfo
CVE-2024-28945 2025-01-20 11:35 2024-04-9 Show GitHub Exploit DB Packet Storm
1327 8.8 重要
Network
マイクロソフト Microsoft OLE DB Driver
Microsoft SQL Server
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-29982 2025-01-20 11:32 2024-04-9 Show GitHub Exploit DB Packet Storm
1328 8.8 重要
Network
マイクロソフト Microsoft OLE DB Driver
Microsoft SQL Server
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-29984 2025-01-20 11:30 2024-04-9 Show GitHub Exploit DB Packet Storm
1329 6.4 警告
Network
Royal Elementor Addons Royal Elementor Addons and Templates Royal Elementor Addons の WordPress 用 Royal Elementor Addons and Templates におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-8482 2025-01-20 11:24 2024-10-8 Show GitHub Exploit DB Packet Storm
1330 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-4121 2025-01-20 11:23 2024-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 11, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
511 - - - reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exp… CWE-79
Cross-site Scripting
CVE-2025-24967 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
512 - - - AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving … CWE-120
Classic Buffer Overflow
CVE-2025-0960 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
513 - - - Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device'… CWE-73
 External Control of File Name or Path
CVE-2025-0630 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
514 - - - A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. - CVE-2025-0509 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
515 - - - DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upl… - CVE-2025-24971 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
516 - - - reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary … CWE-79
Cross-site Scripting
CVE-2025-24966 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
517 - - - Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site W… CWE-1385
 Missing Origin Validation in WebSockets
CVE-2025-24964 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
518 - - - Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the n… CWE-22
Path Traversal
CVE-2025-24963 2025-02-5 05:15 2025-02-5 Show GitHub Exploit DB Packet Storm
519 - - - Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. - CVE-2024-57498 2025-02-5 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
520 - - - ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder. - CVE-2024-57452 2025-02-5 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm