Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1591 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2021-47093 2025-01-17 13:45 2021-12-23 Show GitHub Exploit DB Packet Storm
1592 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2023-52808 2025-01-17 13:45 2023-09-21 Show GitHub Exploit DB Packet Storm
1593 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2024-26829 2025-01-17 13:45 2024-02-1 Show GitHub Exploit DB Packet Storm
1594 4.7 警告
Local
Linux Linux Kernel Linux の Linux Kernel における競合状態に関する脆弱性 CWE-362
CWE-476
CVE-2024-35977 2025-01-17 13:45 2024-04-11 Show GitHub Exploit DB Packet Storm
1595 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2024-56534 2025-01-17 13:45 2024-11-6 Show GitHub Exploit DB Packet Storm
1596 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-56605 2025-01-17 13:45 2024-10-15 Show GitHub Exploit DB Packet Storm
1597 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2021-47455 2025-01-17 13:45 2021-10-20 Show GitHub Exploit DB Packet Storm
1598 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-26749 2025-01-17 13:45 2024-02-19 Show GitHub Exploit DB Packet Storm
1599 7.5 重要
Network
PowerDNS
レッドハット
マイクロソフト
thekelleys
NLnet Labs
CZ.NIC
Fedora Project
日本電気
ISC, Inc.
unbound
Microsoft Windows Server 2019
Dnsmasq
Red Hat Enterprise Linux
ESMPRO/ServerAgent
Microsoft Windows Server 2016
Microsoft W…
MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2023-50387 2025-01-17 13:21 2023-12-7 Show GitHub Exploit DB Packet Storm
1600 7.5 重要
Network
NetApp
日本電気
ISC, Inc.
Active IQ Unified Manager
ESMPRO/ServerAgent
NEC Multimedia OLAP for 映像分析サービス
BIND
ISC, Inc. の BIND 等複数ベンダの製品における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
CWE-789
CVE-2023-6516 2025-01-17 13:19 2023-12-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 24, 2025, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
461 4.3 MEDIUM
Network
- - The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to … CWE-284
Improper Access Control
CVE-2024-13854 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
462 6.1 MEDIUM
Network
- - The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWidgetName’ parameter in all versions up to, and including, 2.31 due to insufficie… CWE-79
Cross-site Scripting
CVE-2024-13736 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
463 5.3 MEDIUM
Network
- - The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on … CWE-862
 Missing Authorization
CVE-2024-13719 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
464 4.9 MEDIUM
Network
- - The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter an… CWE-89
SQL Injection
CVE-2024-13712 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
465 6.1 MEDIUM
Network
- - The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and ou… CWE-79
Cross-site Scripting
CVE-2024-13711 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
466 6.4 MEDIUM
Network
- - The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 due to insufficient input s… CWE-79
Cross-site Scripting
CVE-2024-13679 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
467 6.5 MEDIUM
Network
- - The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and including, 2.0 due to insuffic… CWE-89
SQL Injection
CVE-2024-13676 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
468 6.4 MEDIUM
Network
- - The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions up to, and inc… CWE-79
Cross-site Scripting
CVE-2024-13674 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
469 6.4 MEDIUM
Network
- - The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.4 due to insufficient input sa… CWE-79
Cross-site Scripting
CVE-2024-13663 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm
470 6.4 MEDIUM
Network
- - The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due to insufficient in… CWE-79
Cross-site Scripting
CVE-2024-13660 2025-02-19 17:15 2025-02-19 Show GitHub Exploit DB Packet Storm