Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1411 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft OLE DB Driver
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-28940 2025-01-17 22:14 2024-04-9 Show GitHub Exploit DB Packet Storm
1412 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft OLE DB Driver
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-29046 2025-01-17 22:00 2024-04-9 Show GitHub Exploit DB Packet Storm
1413 8.8 重要
Network
マイクロソフト Microsoft ODBC Driver
Microsoft SQL Server
Microsoft Visual Studio
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-28937 2025-01-17 21:55 2024-04-9 Show GitHub Exploit DB Packet Storm
1414 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows Server 2016
Microsoft Windows Server 2012
Microsoft Windows Server 2019
Microso…
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-362
CWE-416
CWE-591
CVE-2024-49128 2025-01-17 21:48 2024-12-10 Show GitHub Exploit DB Packet Storm
1415 6.8 警告
Physics
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows Server&…
Windows モバイル ブロードバンド ドライバーの特権昇格の脆弱性 CWE-125
CWE-noinfo
CVE-2024-49110 2025-01-17 21:46 2024-12-10 Show GitHub Exploit DB Packet Storm
1416 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2008
Microsoft Window…
Windows Lightweight Directory Access Protocol (LDAP) のリモートでコードが実行される脆弱性 CWE-362
CWE-416
CVE-2024-49127 2025-01-17 21:44 2024-12-10 Show GitHub Exploit DB Packet Storm
1417 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2008
Microsoft Window…
Windows ローカル セキュリティ機関サブシステム サービス (LSASS) のリモートでコードが実行される脆弱性 CWE-362
CWE-416
CWE-591
CVE-2024-49126 2025-01-17 21:42 2024-12-10 Show GitHub Exploit DB Packet Storm
1418 6.6 警告
Physics
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows Server&…
ワイヤレス広域ネットワーク サービス (WwanSvc) の特権昇格の脆弱性 CWE-125
CWE-noinfo
CVE-2024-49111 2025-01-17 21:40 2024-12-10 Show GitHub Exploit DB Packet Storm
1419 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2024-57872 2025-01-17 21:35 2024-11-20 Show GitHub Exploit DB Packet Storm
1420 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における脆弱性 CWE-noinfo
情報不足
CVE-2024-56618 2025-01-17 21:33 2024-12-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 14, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
861 - - - An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injectio… New - CVE-2024-57178 2025-02-11 05:15 2025-02-11 Show GitHub Exploit DB Packet Storm
862 3.1 LOW
Network
- - A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory cor… New CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2025-1153 2025-02-11 04:15 2025-02-11 Show GitHub Exploit DB Packet Storm
863 9.8 CRITICAL
Network
- - The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and includi… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-13011 2025-02-11 04:15 2025-02-11 Show GitHub Exploit DB Packet Storm
864 6.1 MEDIUM
Network
- - The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on the 'search_… New CWE-79
Cross-site Scripting
CVE-2024-13010 2025-02-11 04:15 2025-02-11 Show GitHub Exploit DB Packet Storm
865 - - - Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN… New CWE-345
 Insufficient Verification of Data Authenticity
CVE-2025-25188 2025-02-11 03:15 2025-02-11 Show GitHub Exploit DB Packet Storm
866 - - - An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file. New - CVE-2024-57407 2025-02-11 03:15 2025-02-11 Show GitHub Exploit DB Packet Storm
867 - - - OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department. New - CVE-2024-54954 2025-02-11 03:15 2025-02-11 Show GitHub Exploit DB Packet Storm
868 - - - PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php. New - CVE-2024-48170 2025-02-11 03:15 2025-02-11 Show GitHub Exploit DB Packet Storm
869 3.5 LOW
Network
- - A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of t… Update - CVE-2025-1114 2025-02-11 03:15 2025-02-8 Show GitHub Exploit DB Packet Storm
870 - - - Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified… Update - CVE-2024-55630 2025-02-11 03:15 2025-02-8 Show GitHub Exploit DB Packet Storm