Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187441 5 警告 Longwave Consulting - Drupal 用 Ubercart SecureTrading Payment Method モジュールにおける未払いのアイテムを購入される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4482 2012-11-2 14:36 2012-07-11 Show GitHub Exploit DB Packet Storm
187442 4.3 警告 Joomla! - Joomla! 用 Language Switcher モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4532 2012-11-2 14:01 2012-09-13 Show GitHub Exploit DB Packet Storm
187443 4.3 警告 Joomla! - Joomla! におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4531 2012-11-2 14:00 2012-09-13 Show GitHub Exploit DB Packet Storm
187444 10 危険 General Electric Company - GE Intelligent Platforms Proficy Real-Time Information Portal におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-3026 2012-11-2 13:59 2012-08-14 Show GitHub Exploit DB Packet Storm
187445 10 危険 General Electric Company - GE Intelligent Platforms Proficy Real-Time Information Portal におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-3021 2012-11-2 13:57 2012-08-14 Show GitHub Exploit DB Packet Storm
187446 10 危険 General Electric Company - GE Intelligent Platforms Proficy Real-Time Information Portal におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-3010 2012-11-2 13:57 2012-08-14 Show GitHub Exploit DB Packet Storm
187447 2.1 注意 シトリックス・システムズ - Xen の PV ドメインビルダーにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-4544 2012-11-2 13:52 2012-10-31 Show GitHub Exploit DB Packet Storm
187448 4.3 警告 Pebble - Pebble におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2012-5170 2012-11-2 12:02 2012-11-2 Show GitHub Exploit DB Packet Storm
187449 4.3 警告 Pebble - Pebble における HTTP ヘッダインジェクションの脆弱性 CWE-Other
その他
CVE-2012-4023 2012-11-2 12:02 2012-11-2 Show GitHub Exploit DB Packet Storm
187450 5 警告 Pebble - Pebble において記事が閲覧不能になる脆弱性 CWE-Other
その他
CVE-2012-4022 2012-11-2 12:01 2012-11-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 7, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211 - - - Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slas… New - CVE-2025-1022 2025-02-5 14:15 2025-02-5 Show GitHub Exploit DB Packet Storm
212 - - - An improper input validation the CSRF filter results in unsanitized user input written to the application logs. Update - CVE-2025-24504 2025-02-5 14:15 2025-01-31 Show GitHub Exploit DB Packet Storm
213 - - - A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. Update - CVE-2025-24503 2025-02-5 14:15 2025-01-31 Show GitHub Exploit DB Packet Storm
214 - - - An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address. Update - CVE-2025-24502 2025-02-5 14:15 2025-01-31 Show GitHub Exploit DB Packet Storm
215 - - - An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request. Update - CVE-2025-24501 2025-02-5 14:15 2025-01-31 Show GitHub Exploit DB Packet Storm
216 - - - The vulnerability allows an unauthenticated attacker to access information in PAM database. Update - CVE-2025-24500 2025-02-5 14:15 2025-01-31 Show GitHub Exploit DB Packet Storm
217 8.1 HIGH
Network
- - The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload feature in all versions up to, and including, 8.6.4. Th… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-1028 2025-02-5 13:15 2025-02-5 Show GitHub Exploit DB Packet Storm
218 - - - A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate. New - CVE-2025-23114 2025-02-5 11:15 2025-02-5 Show GitHub Exploit DB Packet Storm
219 - - - Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Paral… New CWE-59
Link Following
CVE-2025-0413 2025-02-5 09:15 2025-02-5 Show GitHub Exploit DB Packet Storm
220 5.4 MEDIUM
Network
- - Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts in… New CWE-79
Cross-site Scripting
CVE-2024-53966 2025-02-5 09:15 2025-02-5 Show GitHub Exploit DB Packet Storm