Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187701 2.1 注意 オラクル - Oracle Solaris 11 における Vino server の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3205 2012-10-19 11:38 2012-10-16 Show GitHub Exploit DB Packet Storm
187702 7.2 危険 オラクル - Oracle Solaris 11 における Power Management の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3204 2012-10-19 11:37 2012-10-16 Show GitHub Exploit DB Packet Storm
187703 2.1 注意 オラクル - Oracle Solaris 11 における Gnome Display Manager の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3203 2012-10-19 11:35 2012-10-16 Show GitHub Exploit DB Packet Storm
187704 7.2 危険 オラクル - Oracle Solaris 10 および 11 における Gnome Trusted Extension の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3199 2012-10-19 11:34 2012-10-16 Show GitHub Exploit DB Packet Storm
187705 7.8 危険 オラクル - Oracle Solaris 11 における COMSTAR の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3189 2012-10-19 11:33 2012-10-16 Show GitHub Exploit DB Packet Storm
187706 6.9 警告 オラクル - Oracle Solaris 10 における Kernel の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3187 2012-10-19 11:32 2012-10-16 Show GitHub Exploit DB Packet Storm
187707 3.6 注意 オラクル - Oracle Solaris における mailx の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3165 2012-10-19 11:30 2012-10-16 Show GitHub Exploit DB Packet Storm
187708 5 警告 サン・マイクロシステムズ
オラクル
- Oracle GlassFish Server および Sun Java System Application Server における CORBA ORB の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3155 2012-10-19 11:28 2012-10-16 Show GitHub Exploit DB Packet Storm
187709 3.3 注意 オラクル - Oracle Database Server の Core RDBMS における脆弱性 CWE-noinfo
情報不足
CVE-2012-3151 2012-10-18 18:17 2012-10-16 Show GitHub Exploit DB Packet Storm
187710 2.1 注意 オラクル - Oracle Database Server の Core RDBMS における脆弱性 CWE-noinfo
情報不足
CVE-2012-3146 2012-10-18 18:16 2012-10-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 12, 2025, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
521 8.8 HIGH
Network
mozilla firefox
thunderbird
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < … CWE-416
 Use After Free
CVE-2025-1010 2025-02-7 04:30 2025-02-4 Show GitHub Exploit DB Packet Storm
522 9.8 CRITICAL
Network
mozilla firefox
thunderbird
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, … CWE-416
 Use After Free
CVE-2025-1009 2025-02-7 04:28 2025-02-4 Show GitHub Exploit DB Packet Storm
523 - - - Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. - CVE-2024-13416 2025-02-7 04:15 2025-02-7 Show GitHub Exploit DB Packet Storm
524 - - - An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been prev… - CVE-2024-43779 2025-02-7 04:15 2025-02-7 Show GitHub Exploit DB Packet Storm
525 - - - A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An… - CVE-2024-39272 2025-02-7 04:15 2025-02-7 Show GitHub Exploit DB Packet Storm
526 - - - MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript… CWE-79
Cross-site Scripting
CVE-2025-24981 2025-02-7 03:15 2025-02-7 Show GitHub Exploit DB Packet Storm
527 - - - mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.1 and below, a malic… CWE-441
CWE-288
Confused Deputy
Authentication Bypass Using an Alternate Path or Channel
CVE-2025-23217 2025-02-7 03:15 2025-02-7 Show GitHub Exploit DB Packet Storm
528 - - - A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter. - CVE-2025-25181 2025-02-7 03:15 2025-02-4 Show GitHub Exploit DB Packet Storm
529 - - - Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be us… - CVE-2024-57968 2025-02-7 03:15 2025-02-4 Show GitHub Exploit DB Packet Storm
530 5.3 MEDIUM
Local
- - A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file … CWE-285
CWE-266
Improper Authorization
 Incorrect Privilege Assignment
CVE-2025-1078 2025-02-7 02:15 2025-02-7 Show GitHub Exploit DB Packet Storm