Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Nov. 6, 2024, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
188871 7.2 危険 GNUstep - GNUstep Base の gdomap の load_iface 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-1620 2012-06-26 16:19 2010-05-12 Show GitHub Exploit DB Packet Storm
188872 6.8 警告 AlegroCart - AlegroCart におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-1611 2012-06-26 16:19 2010-04-29 Show GitHub Exploit DB Packet Storm
188873 4.3 警告 g5-scripts - G5-Scripts Auto-Img-Gallery の upload.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1709 2012-06-26 16:19 2010-05-4 Show GitHub Exploit DB Packet Storm
188874 7.5 危険 RWC - Free Realty の agentadmin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1708 2012-06-26 16:19 2010-05-4 Show GitHub Exploit DB Packet Storm
188875 7.5 危険 2daybiz - 2daybiz Auction Script の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1706 2012-06-26 16:19 2010-05-4 Show GitHub Exploit DB Packet Storm
188876 5 警告 Apache Software Foundation - Apache ActiveMQ の Jetty ResourceHandler における JSP ソースコードを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2010-1587 2012-06-26 16:19 2010-04-28 Show GitHub Exploit DB Packet Storm
188877 7.8 危険 シスコシステムズ - CDS に使用されている Cisco Internet Streamer におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1577 2012-06-26 16:19 2010-07-21 Show GitHub Exploit DB Packet Storm
188878 9 危険 シスコシステムズ - Cisco AXP のテクニカルサポート診断シェルにおける管理者権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2010-1572 2012-06-26 16:19 2010-06-9 Show GitHub Exploit DB Packet Storm
188879 7.8 危険 シスコシステムズ - Cisco UCCX の bootstrap サービスにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1571 2012-06-26 16:19 2010-06-9 Show GitHub Exploit DB Packet Storm
188880 7.8 危険 シスコシステムズ - Cisco UCCX の CTI サーバコンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-1570 2012-06-26 16:19 2010-06-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 7, 2024, 5:21 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 - - - In the Linux kernel, the following vulnerability has been resolved: net: micrel: Fix receiving the timestamp in the frame for lan8841 The blamed commit started to use the ptp workqueue to get the s… Update - CVE-2024-38593 2024-11-7 03:35 2024-06-19 Show GitHub Exploit DB Packet Storm
2 - - - OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device. Update - CVE-2024-22006 2024-11-7 03:35 2024-03-12 Show GitHub Exploit DB Packet Storm
3 - - - The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify fo… Update - CVE-2024-23674 2024-11-7 03:35 2024-02-16 Show GitHub Exploit DB Packet Storm
4 6.5 MEDIUM
Adjacent
elecom wrc-1167ghbk-s_firmware
wrc-1167gebk-s_firmware
wrc-1167febk-s_firmware
wrc-1167ghbk3-a_firmware
wrc-1167febk-a_firmware
ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthorized attacker to obtain sensitive information. Affected products and versions are… Update NVD-CWE-noinfo
CVE-2023-37563 2024-11-7 03:35 2023-07-13 Show GitHub Exploit DB Packet Storm
5 3.3 LOW
Local
google android In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no… Update CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2023-21246 2024-11-7 03:35 2023-07-13 Show GitHub Exploit DB Packet Storm
6 9.8 CRITICAL
Network
nginxui nginx_ui Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, cau… Update NVD-CWE-noinfo
CVE-2024-49368 2024-11-7 03:28 2024-10-22 Show GitHub Exploit DB Packet Storm
7 - - - UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. ¶¶ The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to steali… New - CVE-2024-50637 2024-11-7 03:17 2024-11-7 Show GitHub Exploit DB Packet Storm
8 - - - A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability … New CWE-79
Cross-site Scripting
CVE-2024-20539 2024-11-7 03:17 2024-11-7 Show GitHub Exploit DB Packet Storm
9 - - - A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exis… New CWE-79
Cross-site Scripting
CVE-2024-20538 2024-11-7 03:17 2024-11-7 Show GitHub Exploit DB Packet Storm
10 - - - A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This … New CWE-863
 Incorrect Authorization
CVE-2024-20537 2024-11-7 03:17 2024-11-7 Show GitHub Exploit DB Packet Storm