Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Nov. 14, 2024, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
188841 3.5 注意 Moodle - Moodle の Wiki サブシステムにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2360 2012-07-24 16:05 2012-07-21 Show GitHub Exploit DB Packet Storm
188842 6.5 警告 Moodle - Moodle の admin/roles/override.php における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2359 2012-07-24 16:03 2012-07-21 Show GitHub Exploit DB Packet Storm
188843 5.5 警告 Moodle - Moodle におけるアクティビティの読み取り専用の状態を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2358 2012-07-24 16:00 2012-07-21 Show GitHub Exploit DB Packet Storm
188844 5 警告 Moodle - Moodle の auth/cas/cas_form.html 内 のマルチ認証機能における資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2357 2012-07-24 15:54 2012-07-21 Show GitHub Exploit DB Packet Storm
188845 4 警告 Moodle - Moodle の question-bank 機能における機能制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2356 2012-07-24 15:52 2012-07-21 Show GitHub Exploit DB Packet Storm
188846 4 警告 Moodle - Moodle における question:use* 機能の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2355 2012-07-24 15:51 2012-07-21 Show GitHub Exploit DB Packet Storm
188847 4 警告 Moodle - Moodle における moodle/site:readallmessages 機能の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2354 2012-07-24 15:50 2012-07-21 Show GitHub Exploit DB Packet Storm
188848 4 警告 Moodle - Moodle における非表示フィールドから重要なユーザ情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2353 2012-07-24 15:46 2012-07-21 Show GitHub Exploit DB Packet Storm
188849 7.5 危険 Nullsoft - Winamp の bmp.w5s におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-4045 2012-07-24 15:38 2012-06-28 Show GitHub Exploit DB Packet Storm
188850 5 警告 WordPress.org - WordPress における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3385 2012-07-24 15:38 2012-06-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 15, 2024, 6:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
241 7.8 HIGH
Local
artifex
debian
suse
ghostscript
debian_linux
linux_enterprise_high_performance_computing
linux_enterprise_server
linux_enterprise_server_for_sap
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and… Update CWE-190
 Integer Overflow or Wraparound
CVE-2024-46953 2024-11-14 11:01 2024-11-11 Show GitHub Exploit DB Packet Storm
242 7.8 HIGH
Local
artifex
debian
ghostscript
debian_linux
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values). Update CWE-120
Classic Buffer Overflow
CVE-2024-46952 2024-11-14 11:01 2024-11-11 Show GitHub Exploit DB Packet Storm
243 - - - In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. Th… New - CVE-2024-43093 2024-11-14 11:00 2024-11-14 Show GitHub Exploit DB Packet Storm
244 9.8 CRITICAL
Network
paloaltonetworks expedition Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is … Update CWE-306
Missing Authentication for Critical Function
CVE-2024-5910 2024-11-14 11:00 2024-07-11 Show GitHub Exploit DB Packet Storm
245 7.8 HIGH
Local
artifex ghostscript An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal. Update CWE-22
Path Traversal
CVE-2024-46954 2024-11-14 10:58 2024-11-11 Show GitHub Exploit DB Packet Storm
246 5.5 MEDIUM
Local
artifex
debian
suse
ghostscript
debian_linux
linux_enterprise_high_performance_computing
linux_enterprise_server
linux_enterprise_server_for_sap
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space. Update CWE-125
Out-of-bounds Read
CVE-2024-46955 2024-11-14 10:53 2024-11-11 Show GitHub Exploit DB Packet Storm
247 6.1 MEDIUM
Network
theeventprime eventprime URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5. Update CWE-601
Open Redirect
CVE-2024-47648 2024-11-14 10:53 2024-10-11 Show GitHub Exploit DB Packet Storm
248 9.8 CRITICAL
Network
- - Windows KDC Proxy Remote Code Execution Vulnerability New CWE-197
 Numeric Truncation Error
CVE-2024-43639 2024-11-14 09:15 2024-11-13 Show GitHub Exploit DB Packet Storm
249 6.1 MEDIUM
Network
microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HT… Update CWE-79
Cross-site Scripting
CVE-2024-47604 2024-11-14 08:17 2024-10-2 Show GitHub Exploit DB Packet Storm
250 - - - Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. New - CVE-2024-40410 2024-11-14 08:15 2024-11-14 Show GitHub Exploit DB Packet Storm