Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187011 6.8 警告 X7 Group - X7 Chat におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6047 2012-11-28 15:02 2012-11-27 Show GitHub Exploit DB Packet Storm
187012 10 危険 PHP Enter - PHP Enter の admin/banners.php における horad.php への任意の PHP コード を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6046 2012-11-28 14:57 2012-11-27 Show GitHub Exploit DB Packet Storm
187013 4.3 警告 ramui.com - Ramui Forum の gb/user/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6045 2012-11-28 14:56 2012-11-27 Show GitHub Exploit DB Packet Storm
187014 10 危険 Joobi - Joomla! 用 Jstore コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-5286 2012-11-28 14:55 2012-11-26 Show GitHub Exploit DB Packet Storm
187015 6.8 警告 Open Dynamics - Collabtive の admin.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-5285 2012-11-28 14:32 2012-11-26 Show GitHub Exploit DB Packet Storm
187016 4.3 警告 Open Dynamics - Collabtive におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5284 2012-11-28 14:31 2012-11-26 Show GitHub Exploit DB Packet Storm
187017 6.8 警告 OpenText - OpenText ECM におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-5283 2012-11-28 14:30 2012-11-26 Show GitHub Exploit DB Packet Storm
187018 4.3 警告 OpenText - OpenText ECM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5282 2012-11-28 14:29 2012-11-26 Show GitHub Exploit DB Packet Storm
187019 6.8 警告 net4visions - IBrowser TinyMCE プラグインの CMScout 内の ibrowser.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-5281 2012-11-28 14:27 2012-11-26 Show GitHub Exploit DB Packet Storm
187020 7.5 危険 Joomla-CBE - Joomla! 用 CBE コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-5280 2012-11-28 14:26 2012-11-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 23, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
281 - - - PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on L… New - CVE-2023-51298 2025-02-21 00:15 2025-02-20 Show GitHub Exploit DB Packet Storm
282 - - - PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attack… New - CVE-2023-51296 2025-02-21 00:15 2025-02-20 Show GitHub Exploit DB Packet Storm
283 7.5 HIGH
Network
tp-link tl-wr841nd_firmware A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/WanSlaacCfgRpm.htm. This vulnerability allows attackers to … Update CWE-787
 Out-of-bounds Write
CVE-2025-25901 2025-02-21 00:15 2025-02-14 Show GitHub Exploit DB Packet Storm
284 - - - The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field in all versions up to, and including, 1.8.2 due to insufficient input sanitizati… - CVE-2025-1039 2025-02-20 23:15 2025-02-20 Show GitHub Exploit DB Packet Storm
285 - - - Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting … CWE-276
Incorrect Default Permissions 
CVE-2025-21106 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm
286 - - - Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the … CWE-284
Improper Access Control
CVE-2025-21105 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm
287 6.4 MEDIUM
Network
- - The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' s… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2025-1043 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm
288 - - - A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python co… - CVE-2025-0868 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm
289 7.1 HIGH
Network
- - IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expo… CWE-611
XXE
CVE-2024-49781 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm
290 4.3 MEDIUM
Network
- - IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifyi… CWE-352
 Origin Validation Error
CVE-2024-49779 2025-02-20 21:15 2025-02-20 Show GitHub Exploit DB Packet Storm