Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Nov. 5, 2024, 12:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189051 4.3 警告 FFmpeg - FFmpeg におけるサービス運用妨害 (DoS) の脆弱性 CWE-94
コード・インジェクション
CVE-2009-4636 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189052 9.3 危険 FFmpeg - FFmpeg におけるサービス運用妨害 (DoS) の脆弱性 CWE-94
コード・インジェクション
CVE-2009-4635 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189053 10 危険 FFmpeg - FFmpeg における整数アンダーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-4634 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189054 10 危険 FFmpeg - FFmpeg の vorbis_dec.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2009-4633 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189055 5.8 警告 FFmpeg - FFmpeg の oggparsevorbis.c における重要なメモリコンテンツを取得される脆弱性 CWE-189
数値処理の問題
CVE-2009-4632 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189056 9.3 危険 FFmpeg - FFmpeg の VP3 デコーダにおけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2009-4631 2012-06-26 16:19 2010-02-9 Show GitHub Exploit DB Packet Storm
189057 5 警告 dan brown - Moa Gallery の sources/_template_parser.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4627 2012-06-26 16:19 2010-01-18 Show GitHub Exploit DB Packet Storm
189058 7.5 危険 dan brown - Moa Gallery における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4614 2012-06-26 16:19 2010-01-18 Show GitHub Exploit DB Packet Storm
189059 7.5 危険 fernando soares
Joomla!
- Joomla! 用 Fernando Soares Mamboleto コンポーネントの mamboleto.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4604 2012-06-26 16:19 2010-01-12 Show GitHub Exploit DB Packet Storm
189060 7.5 危険 corephp
Joomla!
- Joomla! の jphoto コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4598 2012-06-26 16:19 2010-01-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 5, 2024, 12:17 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
11 - - - loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All user… New CWE-755
 Improper Handling of Exceptional Conditions
CVE-2024-51502 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
12 - - - Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes (Header, HeaderCollection and Authorize) are vulnerable to CRLF injection. The… New CWE-93
CRLF Injection
CVE-2024-51501 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
13 - - - Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could resu… New CWE-138
CWE-159
CVE-2024-51500 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
14 - - - langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox. New - CVE-2024-48061 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
15 - - - gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket … New - CVE-2024-48059 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
16 - - - localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the paylo… New - CVE-2024-48057 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
17 - - - In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions o… New - CVE-2024-48052 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
18 - - - In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can … New - CVE-2024-48050 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
19 - - - A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the arg… New CWE-89
CWE-74
CWE-707
SQL Injection
Injection
 Improper Enforcement of Message or Data Structure
CVE-2024-10805 2024-11-5 08:15 2024-11-5 Show GitHub Exploit DB Packet Storm
20 7.5 HIGH
Network
- - A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing spec… Update - CVE-2024-10295 2024-11-5 08:15 2024-10-25 Show GitHub Exploit DB Packet Storm