Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1641 8 重要
Adjacent
マイクロソフト Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2012
Microsoft Windows Server&…
セキュア ブートのセキュリティ機能のバイパスの脆弱性 CWE-121
CWE-noinfo
CVE-2024-28925 2025-01-17 10:18 2024-04-9 Show GitHub Exploit DB Packet Storm
1642 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft Visual Studio
Microsoft ODBC Driver
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 CWE-191
CWE-noinfo
CVE-2024-28930 2025-01-17 09:53 2024-04-9 Show GitHub Exploit DB Packet Storm
1643 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft Visual Studio
Microsoft ODBC Driver
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-28935 2025-01-17 09:48 2024-04-9 Show GitHub Exploit DB Packet Storm
1644 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2012
Microso…
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-362
CWE-453
CVE-2024-49120 2025-01-17 09:47 2024-12-10 Show GitHub Exploit DB Packet Storm
1645 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft Visual Studio
Microsoft ODBC Driver
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 CWE-191
CWE-noinfo
CVE-2024-28933 2025-01-17 09:47 2024-04-9 Show GitHub Exploit DB Packet Storm
1646 8.8 重要
Local
マイクロソフト Microsoft Windows 11
Microsoft Windows Server 2022
Microsoft Windows Server 2025
Windows Hyper-V のリモートでコードが実行される脆弱性 CWE-393
CWE-noinfo
CVE-2024-49117 2025-01-17 09:47 2024-12-10 Show GitHub Exploit DB Packet Storm
1647 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft Visual Studio
Microsoft ODBC Driver
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2024-28932 2025-01-17 09:47 2024-04-9 Show GitHub Exploit DB Packet Storm
1648 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server&…
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-362
CWE-591
CVE-2024-49123 2025-01-17 09:47 2024-12-10 Show GitHub Exploit DB Packet Storm
1649 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-53206 2025-01-17 09:44 2024-11-28 Show GitHub Exploit DB Packet Storm
1650 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-56602 2025-01-17 09:44 2024-10-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 11, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
276121 - zeeways zeejobsite Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter. CWE-79
Cross-site Scripting
CVE-2009-4601 2010-01-13 22:15 2010-01-13 Show GitHub Exploit DB Packet Storm
276122 - phpwares php_inventory SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the pr… CWE-89
SQL Injection
CVE-2009-4595 2010-01-13 14:00 2010-01-13 Show GitHub Exploit DB Packet Storm
276123 - drupal randomizer Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via … CWE-79
Cross-site Scripting
CVE-2009-4602 2010-01-13 14:00 2010-01-13 Show GitHub Exploit DB Packet Storm
276124 - zabbix zabbix The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (col… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-4500 2010-01-12 14:00 2010-01-1 Show GitHub Exploit DB Packet Storm
276125 - sun java_system_web_server Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as… NVD-CWE-noinfo
CVE-2010-0273 2010-01-11 22:37 2010-01-9 Show GitHub Exploit DB Packet Storm
276126 - adobe illustrator Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attackers to execute arbitrary code via unspecified vectors. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-3952 2010-01-11 21:25 2010-01-9 Show GitHub Exploit DB Packet Storm
276127 - astha_bhatnagar shindigintegrator Cross-site scripting (XSS) vulnerability in the OpenSocial Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for Drupal, allows remote authenticated users, with "create application" priv… CWE-79
Cross-site Scripting
CVE-2009-4514 2010-01-11 14:00 2010-01-1 Show GitHub Exploit DB Packet Storm
276128 - speedtech storm The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-4515 2010-01-9 05:29 2010-01-1 Show GitHub Exploit DB Packet Storm
276129 - nanwich faq_ask Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requ… CWE-352
 Origin Validation Error
CVE-2009-4517 2010-01-9 02:50 2010-01-1 Show GitHub Exploit DB Packet Storm
276130 - verbatim corporate_secure Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proxima… CWE-310
Cryptographic Issues
CVE-2010-0228 2010-01-8 14:00 2010-01-8 Show GitHub Exploit DB Packet Storm