Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1871 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-6495 2025-01-16 11:26 2024-07-12 Show GitHub Exploit DB Packet Storm
1872 7.8 重要
Local
クアルコム qfw7124 ファームウェア
AR8035 ファームウェア
qamsrv1h ファームウェア
SA6145P ファームウェア
qcn6274 ファームウェア
qcn6224 ファームウェア
qamsrv1m ファームウェア
QCA6584AU ファームウェア
QCA8…
複数のクアルコム製品における古典的バッファオーバーフローの脆弱性 CWE-120
CWE-120
CVE-2023-43525 2025-01-16 11:16 2023-09-19 Show GitHub Exploit DB Packet Storm
1873 4.3 警告
Network
Basixonline NEX-Forms Basixonline の WordPress 用 NEX-Forms における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-0907 2025-01-16 11:16 2024-02-29 Show GitHub Exploit DB Packet Storm
1874 6.5 警告
Network
servit affiliate-toolkit servit の WordPress 用 affiliate-toolkit における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1851 2025-01-16 11:16 2024-03-8 Show GitHub Exploit DB Packet Storm
1875 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1203 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1203 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-2988 2025-01-16 11:16 2024-03-27 Show GitHub Exploit DB Packet Storm
1876 8.8 重要
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3148 2025-01-16 11:16 2024-04-2 Show GitHub Exploit DB Packet Storm
1877 7.8 重要
Local
Rockwell Automation Arena Rockwell Automation の Arena における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-12175 2025-01-16 10:40 2024-12-19 Show GitHub Exploit DB Packet Storm
1878 5.4 警告
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows 10
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Window…
Windows Mark Of The Web セキュリティ機能のバイパスの脆弱性 CWE-693
CWE-noinfo
CVE-2024-30050 2025-01-15 18:15 2024-05-14 Show GitHub Exploit DB Packet Storm
1879 4.1 警告
Network
マイクロソフト Microsoft Dynamics 365 Customer Insights Dynamics 365 Customer Insights のなりすましの脆弱性 CWE-79
CWE-79
CVE-2024-30048 2025-01-15 18:03 2024-05-14 Show GitHub Exploit DB Packet Storm
1880 5.5 警告
Local
マイクロソフト Azure Identity Library .NET 用 Azure Identity ライブラリの情報漏えいの脆弱性 CWE-522
CWE-noinfo
CVE-2024-29992 2025-01-15 17:54 2024-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 13, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
279211 - apache derby Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements… NVD-CWE-Other
CVE-2006-7217 2008-09-6 06:16 2007-07-6 Show GitHub Exploit DB Packet Storm
279212 - sap saplpd
sapsprint
Unspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print job request. NOTE: the provenance of this informati… NVD-CWE-Other
CVE-2006-7220 2008-09-6 06:16 2007-07-10 Show GitHub Exploit DB Packet Storm
279213 - xwiki xwiki PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rig… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-7223 2008-09-6 06:16 2007-09-14 Show GitHub Exploit DB Packet Storm
279214 - scriptphp pronews admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other imp… NVD-CWE-Other
CVE-2006-6580 2008-09-6 06:15 2006-12-16 Show GitHub Exploit DB Packet Storm
279215 - scriptmate user_manager ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box. NVD-CWE-Other
CVE-2006-6583 2008-09-6 06:15 2006-12-16 Show GitHub Exploit DB Packet Storm
279216 - torrentflux torrentflux Cross-site scripting (XSS) vulnerability in dir.php in TorrentFlux 2.2, when allows remote attackers to inject arbitrary web script or HTML via double URL-encoded strings in the dir parameter, a rela… NVD-CWE-Other
CVE-2006-6600 2008-09-6 06:15 2006-12-16 Show GitHub Exploit DB Packet Storm
279217 - moodle moodle Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of th… NVD-CWE-Other
CVE-2006-6625 2008-09-6 06:15 2006-12-18 Show GitHub Exploit DB Packet Storm
279218 - moodle moodle Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG e… NVD-CWE-Other
CVE-2006-6626 2008-09-6 06:15 2006-12-18 Show GitHub Exploit DB Packet Storm
279219 - ibm db2_universal_database IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2… NVD-CWE-Other
CVE-2006-6638 2008-09-6 06:15 2006-12-20 Show GitHub Exploit DB Packet Storm
279220 - chetcpasswd chetcpasswd Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the progra… NVD-CWE-Other
CVE-2006-6639 2008-09-6 06:15 2006-12-20 Show GitHub Exploit DB Packet Storm