Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 10, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189301 6.5 警告 Joomla! - Joomla! における任意のユーザを管理者グループへ昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6644 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189302 4.3 警告 Joomla! - Joomla! の com_poll コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6643 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189303 10 危険 Bharat Mediratta - Menalto Gallery の Publish XP モジュールにおけるアルバムを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6685 2012-09-25 16:59 2007-12-24 Show GitHub Exploit DB Packet Storm
189304 5 警告 mortbay jetty - Mortbay Jetty におけるファイルのソースを読まれる脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6672 2012-09-25 16:59 2007-07-9 Show GitHub Exploit DB Packet Storm
189305 6.8 警告 Joomla! - Joomla! におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6642 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189306 4.3 警告 milliscripts - milliscripts Redirection の dir.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6641 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189307 7.5 危険 iptbb team - IPTBB の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6639 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189308 10 危険 march networks - March Networks DVR 3204 におけるユーザ名などを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6638 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189309 6.4 警告 netbizcity - FAQMasterFlexPlus におけるパスワードを取得される脆弱性 CWE-310
暗号の問題
CVE-2007-6635 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
189310 6.8 警告 netbizcity - FAQMasterFlexPlus における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6634 2012-09-25 16:59 2008-01-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 10, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 - - - Rejected reason: reserved but not needed New - CVE-2024-45345 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
202 - - - Rejected reason: reserved but not needed New - CVE-2024-45344 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
203 - - - Rejected reason: reserved but not needed New - CVE-2024-45343 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
204 - - - Rejected reason: reserved but not needed New - CVE-2024-45342 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
205 - - - WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerabi… New - CVE-2025-22141 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
206 - - - WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente paramete… New - CVE-2025-22140 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
207 - - - WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This vulnerabi… New - CVE-2025-22139 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
208 - - - Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) New CWE-843
Type Confusion
CVE-2025-0291 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
209 - - - SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list. New - CVE-2024-54818 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm
210 - - - Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file. New - CVE-2024-51442 2025-01-9 05:15 2025-01-9 Show GitHub Exploit DB Packet Storm