Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187421 7.5 危険 ヒューレット・パッカード
VMware
OpenSSL Project
- OpenSSL における共有秘密鍵の認証要求を回避される脆弱性 CWE-287
不適切な認証
CVE-2010-4252 2012-11-2 17:36 2010-11-29 Show GitHub Exploit DB Packet Storm
187422 6.4 警告 Gecad Technologies - Axigen Free Mail Server にディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-4940 2012-11-2 16:48 2012-10-31 Show GitHub Exploit DB Packet Storm
187423 4.3 警告 SolarWinds - Orion IPAM にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4939 2012-11-2 16:48 2012-10-31 Show GitHub Exploit DB Packet Storm
187424 3.5 注意 Justin Dodge - Drupal 用 Hotblocks モジュールの設定ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5705 2012-11-2 16:16 2012-08-15 Show GitHub Exploit DB Packet Storm
187425 3.5 注意 Justin Dodge - Drupal 用 Hotblocks モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-5704 2012-11-2 16:15 2012-08-15 Show GitHub Exploit DB Packet Storm
187426 7.8 危険 TP-LINK Technologies - TP-LINK TL-WR841N ルータ上で稼働する Web ベースの管理機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-5687 2012-11-2 16:13 2012-11-1 Show GitHub Exploit DB Packet Storm
187427 10 危険 シーメンス - Siemens SiPass integrated のサーバにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2012-5409 2012-11-2 16:03 2012-10-8 Show GitHub Exploit DB Packet Storm
187428 3.5 注意 Nancy Wichmann - Drupal 用 Announcements モジュール におけるノードのアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4500 2012-11-2 15:06 2012-08-28 Show GitHub Exploit DB Packet Storm
187429 5 警告 Matthias Hutterer - Drupal 用 Email Field モジュールにおけるエンティティに格納されたアドレスに電子メールを送信される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4499 2012-11-2 15:04 2012-08-29 Show GitHub Exploit DB Packet Storm
187430 2.1 注意 inclind - Drupal 用 Custom Publishing Options モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4496 2012-11-2 15:04 2012-08-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 12, 2025, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
511 - - - Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working state. - CVE-2024-13417 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
512 - - - Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authen… - CVE-2024-57523 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
513 - - - WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database connection strings, which allows an attacker to read local file… - CVE-2025-24787 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
514 - - - WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an … - CVE-2025-24786 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
515 - - - Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuth… - CVE-2025-24860 2025-02-7 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
516 - - - SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied paramete… - CVE-2025-25064 2025-02-7 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
517 4.3 MEDIUM
Network
mozilla firefox
thunderbird
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2025-1019 2025-02-7 04:40 2025-02-4 Show GitHub Exploit DB Packet Storm
518 5.3 MEDIUM
Network
mozilla firefox
thunderbird
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affect… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2025-1018 2025-02-7 04:40 2025-02-4 Show GitHub Exploit DB Packet Storm
519 7.5 HIGH
Network
mozilla firefox
thunderbird
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird <… CWE-416
 Use After Free
CVE-2025-1012 2025-02-7 04:33 2025-02-4 Show GitHub Exploit DB Packet Storm
520 8.8 HIGH
Network
mozilla firefox
thunderbird
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefo… NVD-CWE-noinfo
CVE-2025-1011 2025-02-7 04:31 2025-02-4 Show GitHub Exploit DB Packet Storm