You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
|
Update Date":Jan. 21, 2025, 10:02 a.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
151 | 5.4 |
警告
Network |
Sonaar Music |
mp3 audio player for music radio & podcast |
Sonaar Music の WordPress 用 mp3 audio player for music, radio & podcast におけるクロスサイトスクリプティングの脆弱性 New |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2024-10268 | 2025-01-20 12:21 | 2024-11-19 | Show | GitHub Exploit DB Packet Storm |
152 | 4.3 |
警告
Network |
webinarpress | webinarpress | WordPress 用 webinarpress における認証の欠如に関する脆弱性 New |
CWE-862
認証の欠如 |
CVE-2024-11271 | 2025-01-20 12:21 | 2024-11-15 | Show | GitHub Exploit DB Packet Storm |
153 | 5.4 |
警告
Network |
wpextended | The Ultimate WordPress Toolkit - WP Extended | wpextended の WordPress 用 The Ultimate WordPress Toolkit - WP Extended におけるクロスサイトスクリプティングの脆弱性 New |
CWE-79 CWE-862 |
CVE-2024-11916 | 2025-01-20 12:21 | 2024-11-27 | Show | GitHub Exploit DB Packet Storm |
154 | 4.3 |
警告
Network |
Hire Web Xperts | Passwords Manager | Hire Web Xperts の WordPress 用 Passwords Manager における認証の欠如に関する脆弱性 New |
CWE-862 CWE-89 |
CVE-2024-12614 | 2025-01-20 12:21 | 2024-12-13 | Show | GitHub Exploit DB Packet Storm |
155 | 9.8 |
緊急
Network oretnom23 |
Laundry Shop Management System
|
oretnom23 の Laundry Shop Management System における SQL インジェクションの脆弱性
New
|
CWE-89
|
SQLインジェクション
CVE-2024-3465
|
2025-01-20 12:03 |
2024-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
156 | 9.8 |
緊急
Network Shenzhen Tenda Technology Co.,Ltd. |
ac500 ファームウェア
|
Shenzhen Tenda Technology Co.,Ltd. の ac500 ファームウェアにおける境界外書き込みに関する脆弱性
New
|
CWE-121 |
CWE-787
CVE-2024-3907
|
2025-01-20 12:03 |
2024-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
157 | 7.8 |
重要
Local |
Ivanti | secure access client | Ivanti の secure access client における脆弱性 New |
CWE-267 CWE-Other |
CVE-2024-7571 | 2025-01-20 12:02 | 2024-11-12 | Show | GitHub Exploit DB Packet Storm |
158 | 3.3 |
低
Local |
Ivanti | secure access client | Ivanti の secure access client における脆弱性 New |
CWE-267 CWE-732 CWE-732 CWE-Other |
CVE-2024-9842 | 2025-01-20 12:02 | 2024-11-12 | Show | GitHub Exploit DB Packet Storm |
159 | 7.8 |
重要
Local |
Linux | Linux Kernel | Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 New |
CWE-416
解放済みメモリの使用 |
CVE-2024-53208 | 2025-01-20 11:59 | 2024-11-26 | Show | GitHub Exploit DB Packet Storm |
160 | 5.3 |
警告
Network IBM |
Jazz Foundation
|
IBM の Jazz Foundation における脆弱性
New
|
CWE-266 |
CWE-noinfo
CVE-2023-26280
|
2025-01-20 11:59 |
2023-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
Update Date:Jan. 21, 2025, 4:11 a.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
441 | 8.8 |
HIGH
Network |
chrome | Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CWE-125
Out-of-bounds Read |
CVE-2025-0437 | 2025-01-17 05:35 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm | |
442 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2022_23h2 windows_11_23h2 windows_10_1607 windows_10_1809 windows_10_1507 windows_10_21h2 windows_10_22h2 windows_11_… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21417 | 2025-01-17 05:34 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
443 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21413 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
444 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21411 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
445 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21409 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
446 | - | - | - | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carrotbits Greek Namedays Widget From Eortologio.Net allows Stored XSS.This issue affects Greek N… |
CWE-79
Cross-site Scripting |
CVE-2025-23783 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
447 | - | - | - | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revolutionart Marmoset Viewer allows Stored XSS.This issue affects Marmoset Viewer: from n/a thro… |
CWE-79
Cross-site Scripting |
CVE-2025-23767 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
448 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Mahdi Khaksar mybb Last Topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through 1.0. |
CWE-352
Origin Validation Error |
CVE-2025-23749 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
449 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor internet & marketing Call me Now allows Stored XSS.This issue affects Call me Now: from n/a through 1.0.5. |
CWE-352
Origin Validation Error |
CVE-2025-23745 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
450 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Martijn Scheybeler Social Analytics allows Stored XSS.This issue affects Social Analytics: from n/a through 0.2. |
CWE-352
Origin Validation Error |
CVE-2025-23743 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm |