Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187911 2.1 注意 Cartpauj.com - WordPress 用 Shortcode Redirect プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5325 2012-10-11 15:01 2012-10-8 Show GitHub Exploit DB Packet Storm
187912 9.3 危険 Tracker Software Products - Tracker Software PDF-XChange の pdfxctrl.dll におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-5324 2012-10-11 15:00 2012-10-8 Show GitHub Exploit DB Packet Storm
187913 4.3 警告 k5n.us - Craig Knudsen WebCalendar におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0846 2012-10-11 14:58 2012-01-11 Show GitHub Exploit DB Packet Storm
187914 6.8 警告 XAVi Technologies - Xavi X7968 におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-5323 2012-10-11 14:57 2012-10-8 Show GitHub Exploit DB Packet Storm
187915 4.3 警告 XAVi Technologies - Xavi X7968 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5322 2012-10-11 14:57 2012-10-8 Show GitHub Exploit DB Packet Storm
187916 5.8 警告 Tiki Software Community Association - TikiWiki CMS/Groupware における任意の Web サイトのページをロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2012-5321 2012-10-11 14:55 2012-10-8 Show GitHub Exploit DB Packet Storm
187917 6.8 警告 Sagemcom - Sagem F@ST 2604 の password.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-5320 2012-10-11 14:53 2012-10-8 Show GitHub Exploit DB Packet Storm
187918 6.8 警告 D-Link Systems, Inc. - 複数の D-Link 製品の setup/security.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-5319 2012-10-11 14:48 2012-10-8 Show GitHub Exploit DB Packet Storm
187919 6.8 警告 SocialCMS - SocialCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-1416 2012-10-11 14:42 2012-10-8 Show GitHub Exploit DB Packet Storm
187920 6.8 警告 D-Link Systems, Inc. - D-Link DSL-2640B ファームウェアの redpass.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-1308 2012-10-11 14:38 2012-10-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 5, 2025, 4:56 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
231 6.6 MEDIUM
Local
- - Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls. New CWE-416
 Use After Free
CVE-2024-38411 2025-02-4 02:15 2025-02-4 Show GitHub Exploit DB Packet Storm
232 7.5 HIGH
Network
- - Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. New CWE-126
 Buffer Over-read
CVE-2024-38404 2025-02-4 02:15 2025-02-4 Show GitHub Exploit DB Packet Storm
233 - - - macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state. Update - CVE-2024-57433 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
234 - - - In EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0, the AES encryption keys used to encrypt passwords are not stored securely. Update - CVE-2024-53357 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
235 - - - A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP request… Update - CVE-2025-23001 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
236 - - - A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain … Update - CVE-2025-22957 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
237 - - - macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subs… Update - CVE-2024-57432 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
238 - - - OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. Update - CVE-2024-53584 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
239 - - - SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing Priv… Update - CVE-2024-47857 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm
240 - - - A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware … Update - CVE-2024-42671 2025-02-4 02:15 2025-02-1 Show GitHub Exploit DB Packet Storm