Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1331 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-4586 2025-01-20 11:23 2024-05-7 Show GitHub Exploit DB Packet Storm
1332 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4379 2025-01-20 11:23 2024-05-31 Show GitHub Exploit DB Packet Storm
1333 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-4592 2025-01-20 11:23 2024-05-7 Show GitHub Exploit DB Packet Storm
1334 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-4122 2025-01-20 11:23 2024-04-24 Show GitHub Exploit DB Packet Storm
1335 5.4 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4449 2025-01-20 11:23 2024-05-14 Show GitHub Exploit DB Packet Storm
1336 5.4 警告
Network
Jegtheme Jeg Elementor Kit Jegtheme の WordPress 用 Jeg Elementor Kit におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-87
CVE-2024-3162 2025-01-20 11:22 2024-04-3 Show GitHub Exploit DB Packet Storm
1337 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-3006 2025-01-20 11:22 2024-03-27 Show GitHub Exploit DB Packet Storm
1338 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2024-3009 2025-01-20 11:22 2024-03-28 Show GitHub Exploit DB Packet Storm
1339 5.4 警告
Network
Royal Elementor Addons Royal Elementor Addons and Templates Royal Elementor Addons の WordPress 用 Royal Elementor Addons and Templates におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3887 2025-01-20 11:22 2024-05-16 Show GitHub Exploit DB Packet Storm
1340 5.4 警告
Network
g5plus ultimate bootstrap elements for elementor g5plus の WordPress 用 ultimate bootstrap elements for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2132 2025-01-20 11:20 2024-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
276131 - claudio_matsuoka extended_module_player Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm func… CWE-94
Code Injection
CVE-2007-6731 2009-09-14 13:00 2009-09-14 Show GitHub Exploit DB Packet Storm
276132 - claudio_matsuoka extended_module_player Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors relate… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-6732 2009-09-14 13:00 2009-09-14 Show GitHub Exploit DB Packet Storm
276133 - rivetcode rivettracker RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php. CWE-310
Cryptographic Issues
CVE-2008-7207 2009-09-12 01:30 2009-09-12 Show GitHub Exploit DB Packet Storm
276134 - marc_gloor screenie screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file. CWE-59
Link Following
CVE-2008-5371 2009-09-11 14:29 2008-12-9 Show GitHub Exploit DB Packet Storm
276135 - cmus cmus cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file. CWE-59
Link Following
CVE-2008-5375 2009-09-11 14:29 2008-12-9 Show GitHub Exploit DB Packet Storm
276136 - multi-website multi_website Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI. CWE-79
Cross-site Scripting
CVE-2009-3162 2009-09-11 13:00 2009-09-11 Show GitHub Exploit DB Packet Storm
276137 - openwebmail.acatysmoof openwebmail Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors. CWE-79
Cross-site Scripting
CVE-2008-7202 2009-09-11 13:00 2009-09-10 Show GitHub Exploit DB Packet Storm
276138 - allenthusiast reviewpost_php_pro Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter. CWE-79
Cross-site Scripting
CVE-2009-3147 2009-09-11 03:30 2009-09-11 Show GitHub Exploit DB Packet Storm
276139 - mark_reinsfelder metashell Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability. NVD-CWE-noinfo
CVE-2008-7196 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm
276140 - g15tools g15daemon Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2008-7197 2009-09-10 19:30 2009-09-10 Show GitHub Exploit DB Packet Storm