Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1601 5.3 警告
Network
NetApp
日本電気
ISC, Inc.
Active IQ Unified Manager
ESMPRO/ServerAgent
NEC Multimedia OLAP for 映像分析サービス
BIND
ISC, Inc. の BIND 等複数ベンダの製品における脆弱性 CWE-noinfo
情報不足
CVE-2023-5680 2025-01-17 13:18 2023-10-20 Show GitHub Exploit DB Packet Storm
1602 7.5 重要
Network
日本電気
Fedora Project
NetApp
ISC, Inc.
ESMPRO/ServerAgent
NEC Multimedia OLAP for 映像分析サービス
Active IQ Unified Manager
Fedora
BIND
NetApp の Active IQ Unified Manager 等複数ベンダの製品における脆弱性 CWE-noinfo
情報不足
CVE-2023-5679 2025-01-17 13:13 2023-10-20 Show GitHub Exploit DB Packet Storm
1603 7.5 重要
Network
日本電気
Fedora Project
NetApp
ISC, Inc.
ESMPRO/ServerAgent
NEC Multimedia OLAP for 映像分析サービス
Active IQ Unified Manager
Fedora
BIND
NetApp の Active IQ Unified Manager 等複数ベンダの製品における到達可能なアサーションに関する脆弱性 CWE-617
CWE-617
CVE-2023-5517 2025-01-17 13:12 2023-10-11 Show GitHub Exploit DB Packet Storm
1604 7.5 重要
Network
Fedora Project
日本電気
ISC, Inc.
NEC Multimedia OLAP for 映像分析サービス
Fedora
ESMPRO/ServerAgent
BIND
NetApp の ONTAP (旧 Clustered Data ONTAP) 等複数ベンダの製品における脆弱性 CWE-noinfo
情報不足
CVE-2023-4408 2025-01-17 13:10 2023-08-18 Show GitHub Exploit DB Packet Storm
1605 9.8 緊急
Network
Apache Software Foundation Apache Struts Apache Struts 2 における外部からアクセス可能なファイルの脆弱性 (S2-066) CWE-552
外部からアクセス可能なファイルまたはディレクトリ
CVE-2023-50164 2025-01-17 12:58 2023-12-8 Show GitHub Exploit DB Packet Storm
1606 9.8 緊急
Network
Apache Software Foundation hertzbeat Apache Software Foundation の hertzbeat におけるインジェクションに関する脆弱性 CWE-74
CWE-74
CVE-2023-51388 2025-01-17 12:08 2023-12-18 Show GitHub Exploit DB Packet Storm
1607 9.8 緊急
Network
Ivanti Avalanche Ivanti の Avalanche におけるパストラバーサルの脆弱性 CWE-22
CWE-22
CWE-288
CVE-2024-13179 2025-01-17 12:08 2025-01-14 Show GitHub Exploit DB Packet Storm
1608 5.4 警告
Network
Themeisle Orbit Fox ThemeIsle の WordPress 用 Orbit Fox におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-13183 2025-01-17 12:08 2025-01-10 Show GitHub Exploit DB Packet Storm
1609 4.3 警告
Network
Progress Software Corporation MOVEit Transfer Progress Software Corporation の MOVEit Transfer における脆弱性 CWE-778
CWE-Other
CVE-2024-2291 2025-01-17 12:08 2024-03-20 Show GitHub Exploit DB Packet Storm
1610 4.8 警告
Network
MantisBT Group MantisBT MantisBT Group の MantisBT におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-34081 2025-01-17 12:08 2024-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 23, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
551 5.4 MEDIUM
Network
jeremyshapiro fusedesk The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' shortcode in all versions up to, and including, 6.6.1 due to insufficient input sani… CWE-79
Cross-site Scripting
CVE-2024-13459 2025-02-19 04:11 2025-02-12 Show GitHub Exploit DB Packet Storm
552 7.5 HIGH
Network
wpfactory customer_email_verification_for_woocommerce The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode tha… NVD-CWE-noinfo
CVE-2024-13528 2025-02-19 03:53 2025-02-12 Show GitHub Exploit DB Packet Storm
553 6.1 MEDIUM
Network
anisha job_recruitment A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation … CWE-79
Cross-site Scripting
CVE-2025-1190 2025-02-19 03:47 2025-02-12 Show GitHub Exploit DB Packet Storm
554 7.5 HIGH
Network
wiselyhub js_help_desk The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdat… NVD-CWE-noinfo
CVE-2024-13606 2025-02-19 03:46 2025-02-13 Show GitHub Exploit DB Packet Storm
555 6.1 MEDIUM
Network
tangiblewp listivo The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 2.3.67 due to insufficient… CWE-79
Cross-site Scripting
CVE-2024-13867 2025-02-19 03:41 2025-02-13 Show GitHub Exploit DB Packet Storm
556 7.8 HIGH
Local
dell supportassist Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leadi… CWE-59
Link Following
CVE-2025-22480 2025-02-19 03:39 2025-02-14 Show GitHub Exploit DB Packet Storm
557 - - - An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges. - CVE-2024-51505 2025-02-19 03:15 2025-02-19 Show GitHub Exploit DB Packet Storm
558 - - - Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens using … CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2025-26620 2025-02-19 03:15 2025-02-19 Show GitHub Exploit DB Packet Storm
559 3.8 LOW
Network
- - A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, … CWE-20
 Improper Input Validation 
CVE-2024-4028 2025-02-19 03:15 2025-02-19 Show GitHub Exploit DB Packet Storm
560 - - - Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. Due to missed checks… - CVE-2023-34402 2025-02-19 03:15 2025-02-14 Show GitHub Exploit DB Packet Storm