Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 2, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189211 5.8 警告 vBulletin Solutions, Inc. - vBulletin におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3326 2012-09-25 16:47 2007-06-21 Show GitHub Exploit DB Packet Storm
189212 7.5 危険 LMS Developers - LMS の lib/language.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3325 2012-09-25 16:47 2007-06-21 Show GitHub Exploit DB Packet Storm
189213 7.5 危険 The PHP Group - PHP の Tidy エクステンションにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-3294 2012-09-25 16:47 2007-06-20 Show GitHub Exploit DB Packet Storm
189214 7.5 危険 livecms - LiveCMS の categoria.php における SQL インジェクションの脆弱性 - CVE-2007-3293 2012-09-25 16:47 2007-06-20 Show GitHub Exploit DB Packet Storm
189215 7.5 危険 livecms - LiveCMS における任意の PHP コードをアップロードされる脆弱性 - CVE-2007-3292 2012-09-25 16:47 2007-06-20 Show GitHub Exploit DB Packet Storm
189216 4.3 警告 livecms - LiveCMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3291 2012-09-25 16:47 2007-06-20 Show GitHub Exploit DB Packet Storm
189217 9.3 危険 livecms - LiveCMS の categoria.php における重要な情報を取得される脆弱性 - CVE-2007-3290 2012-09-25 16:47 2007-06-20 Show GitHub Exploit DB Packet Storm
189218 7.8 危険 マイクロソフト - Microsoft Office MSODataSourceControl ActiveX オブジェクトにおけるバッファオーバーフローの脆弱性 - CVE-2007-3282 2012-09-25 16:47 2007-06-19 Show GitHub Exploit DB Packet Storm
189219 4.3 警告 php hosting biller - Php Hosting Biller の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3281 2012-09-25 16:47 2007-06-19 Show GitHub Exploit DB Packet Storm
189220 7.1 危険 mailwasher - MailWasher Server における任意のユーザアカウントへアクセスされる脆弱性 CWE-255
証明書・パスワード管理
CVE-2007-3275 2012-09-25 16:47 2007-06-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 2, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221 - - - A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Front-end/faculty.php. The manipulation of the ar… New - CVE-2024-13025 2024-12-31 03:15 2024-12-30 Show GitHub Exploit DB Packet Storm
222 - - - A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Affected by this issue is some unknown functionality of the file /endpoint/add-mar… New - CVE-2024-13021 2024-12-31 03:15 2024-12-30 Show GitHub Exploit DB Packet Storm
223 - - - The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks eve… Update - CVE-2024-11223 2024-12-31 03:15 2024-12-26 Show GitHub Exploit DB Packet Storm
224 - - - The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisi… Update - CVE-2024-10903 2024-12-31 03:15 2024-12-26 Show GitHub Exploit DB Packet Storm
225 - - - Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially al… New CWE-601
Open Redirect
CVE-2024-56734 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm
226 - - - LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability in the `Referer` HTTP heade… New CWE-79
Cross-site Scripting
CVE-2024-56517 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm
227 - - - free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format. In versions up to and including 1.0.1, MD5 is used to hash passwords bef… New CWE-328
 Use of Weak Hash
CVE-2024-56516 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm
228 - - - Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Del… New CWE-843
Type Confusion
CVE-2024-12836 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm
229 - - - Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session … New CWE-384
 Session Fixation
CVE-2024-56733 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm
230 - - - Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR) vulnerability in the update_subscription endpoint allows any authenticated us… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-52294 2024-12-31 02:15 2024-12-31 Show GitHub Exploit DB Packet Storm