Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
186931 7.5 危険 Joomla! - Joomla! における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1598 2012-12-5 11:55 2012-03-27 Show GitHub Exploit DB Packet Storm
186932 10 危険 Google - Google Chrome における脆弱性 CWE-noinfo
情報不足
CVE-2012-5138 2012-12-5 11:48 2012-11-29 Show GitHub Exploit DB Packet Storm
186933 10 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-5137 2012-12-5 11:46 2012-11-29 Show GitHub Exploit DB Packet Storm
186934 7.5 危険 Google - Google Chrome OS の WebGL サブシステムにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-5129 2012-12-5 11:39 2012-11-30 Show GitHub Exploit DB Packet Storm
186935 7.5 危険 David Alkire - Drupal 用 Drag & Drop Gallery モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-4479 2012-12-4 16:28 2012-07-11 Show GitHub Exploit DB Packet Storm
186936 6.8 警告 David Alkire - Drupal 用 Drag & Drop Gallery モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-4478 2012-12-4 16:27 2012-07-11 Show GitHub Exploit DB Packet Storm
186937 5 警告 David Alkire - Drupal 用 Drag & Drop Gallery モジュールにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4477 2012-12-4 16:27 2012-07-11 Show GitHub Exploit DB Packet Storm
186938 4.3 警告 David Alkire - Drupal 用 Drag & Drop Gallery モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4476 2012-12-4 16:26 2012-07-11 Show GitHub Exploit DB Packet Storm
186939 5 警告 Chris Hertzog - Drupal 用 Security Questions モジュールにおける任意のユーザの質問および回答を編集される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4475 2012-12-4 16:26 2012-07-11 Show GitHub Exploit DB Packet Storm
186940 4.3 警告 Dennis Blake - Drupal 用 Colorbox Node モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4474 2012-12-4 16:24 2012-07-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 19, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
41 - - - A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functi… New - CVE-2025-1023 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
42 - - - A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This … New - CVE-2025-0981 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
43 6.5 MEDIUM
Network
- - The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insuffici… New CWE-89
SQL Injection
CVE-2024-13369 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
44 4.3 MEDIUM
Network
- - The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due … New CWE-352
 Origin Validation Error
CVE-2024-13718 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
45 6.4 MEDIUM
Network
- - The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitiza… New CWE-79
Cross-site Scripting
CVE-2024-13395 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
46 5.3 MEDIUM
Network
- - The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability… New CWE-862
 Missing Authorization
CVE-2024-13316 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
47 9.8 CRITICAL
Network
- - The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plug… New CWE-620
 Unverified Password Change
CVE-2024-12860 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
48 6.1 MEDIUM
Network
- - The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up… New CWE-79
Cross-site Scripting
CVE-2025-0864 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm
49 - - - Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as th… New - CVE-2025-0425 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm
50 - - - In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able … New - CVE-2025-0424 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm