Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
141 7.5 重要
Network
WP eCommerce WP eCommerce WordPress 用 WP eCommerce における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-1514 2025-01-30 12:03 2024-02-28 Show GitHub Exploit DB Packet Storm
142 7.5 重要
Network
CE21, LLC CE21 Suite CE21, LLC の WordPress 用 CE21 Suite における脆弱性 CWE-200
CWE-noinfo
CVE-2024-10285 2025-01-30 12:01 2024-11-9 Show GitHub Exploit DB Packet Storm
143 7.8 重要
Local
アップル iOS
tvOS
iPadOS
watchOS
visionos
複数のアップル製品における解放済みメモリの使用に関する脆弱性 CWE-416
CWE-416
CVE-2025-24085 2025-01-30 12:01 2025-01-27 Show GitHub Exploit DB Packet Storm
144 9.8 緊急
Network
netentsec application security gateway netentsec の application security gateway における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-5773 2025-01-30 11:55 2024-06-9 Show GitHub Exploit DB Packet Storm
145 5.4 警告
Network
bdthemes element pack bdthemes の WordPress 用 element pack におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-7247 2025-01-30 11:55 2024-08-13 Show GitHub Exploit DB Packet Storm
146 5.4 警告
Network
codeless cowidgets elementor addons codeless の WordPress 用 cowidgets elementor addons におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-8960 2025-01-30 11:55 2024-11-9 Show GitHub Exploit DB Packet Storm
147 4.3 警告
Network
WPMU DEV forminator forms WPMU DEV の WordPress 用 forminator forms におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-9352 2025-01-30 11:55 2024-10-17 Show GitHub Exploit DB Packet Storm
148 6.5 警告
Network
インターネット技術タスクフォース (IETF) IPv6 インターネット技術タスクフォース (IETF) の IPv6 における脆弱性 CWE-940
CWE-Other
CVE-2025-23019 2025-01-30 11:55 2025-01-14 Show GitHub Exploit DB Packet Storm
149 5.4 警告
Network
nsqua simply schedule appointments nsqua の WordPress 用 simply schedule appointments におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4288 2025-01-30 11:48 2024-05-16 Show GitHub Exploit DB Packet Storm
150 5.4 警告
Network
bdthemes element pack bdthemes の WordPress 用 element pack におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-4360 2025-01-30 11:48 2024-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 11, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274001 - joomla joomla Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to… CWE-20
 Improper Input Validation 
CVE-2006-4466 2011-10-11 13:00 2006-09-1 Show GitHub Exploit DB Packet Storm
274002 - freebsd freebsd Integer overflow in the ffs_mountfs function in FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted UFS filesystem that causes invali… CWE-189
Numeric Errors
CVE-2006-5679 2011-10-11 13:00 2006-11-4 Show GitHub Exploit DB Packet Storm
274003 - apple mac_os_x Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource … CWE-264
CWE-20
Permissions, Privileges, and Access Controls
 Improper Input Validation 
CVE-2007-6165 2011-10-6 13:00 2007-11-29 Show GitHub Exploit DB Packet Storm
274004 - vilistextum vilistextum Memory leak in the push_align function in src/util.c in Vilistextum before 2.6.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the tmp_a… CWE-399
 Resource Management Errors
CVE-2006-5656 2011-10-3 13:00 2006-11-3 Show GitHub Exploit DB Packet Storm
274005 - debian horde
horde_groupware
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files vi… CWE-22
Path Traversal
CVE-2009-0932 2011-09-22 12:07 2009-03-18 Show GitHub Exploit DB Packet Storm
274006 - seattle_lab_software slnet_rf_telnet_server SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2008-0152 2011-09-21 13:00 2008-01-9 Show GitHub Exploit DB Packet Storm
274007 - zenturi zenturi_programchecker Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) Debu… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2987 2011-09-20 13:00 2007-06-1 Show GitHub Exploit DB Packet Storm
274008 - zenturi zenturi_programchecker Failed exploit attempts will likely result in denial-of-service condition. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2987 2011-09-20 13:00 2007-06-1 Show GitHub Exploit DB Packet Storm
274009 - kernel
linux
linux_kernel The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of ser… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-3288 2011-09-15 12:06 2009-09-22 Show GitHub Exploit DB Packet Storm
274010 - webmin usermin
webmin
Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2)… CWE-79
Cross-site Scripting
CVE-2007-3156 2011-09-13 13:00 2007-06-12 Show GitHub Exploit DB Packet Storm