Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189441 4.3 警告 IBM - IBM Rational ClearQuest の CQWeb サーバにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2211 2012-09-25 17:27 2009-06-23 Show GitHub Exploit DB Packet Storm
189442 5 警告 pc4arb - Pc4 Uploader の upfiles/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2180 2012-09-25 17:27 2009-06-23 Show GitHub Exploit DB Packet Storm
189443 4.3 警告 henning makholm - xcftools の flattenIncrementally 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2175 2012-09-25 17:27 2009-06-23 Show GitHub Exploit DB Packet Storm
189444 5 警告 gupnp - GUPnP におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2009-2174 2012-09-25 17:27 2009-06-23 Show GitHub Exploit DB Packet Storm
189445 4 警告 Mahara - Mahara における他のユーザのアーティファクトを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2171 2012-09-25 17:27 2009-06-21 Show GitHub Exploit DB Packet Storm
189446 4.3 警告 Mahara - Mahara におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2170 2012-09-25 17:27 2009-06-21 Show GitHub Exploit DB Packet Storm
189447 5 警告 OCS Inventory Team - OCS Inventory NG の cvs.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2166 2012-09-25 17:27 2009-06-22 Show GitHub Exploit DB Packet Storm
189448 6.8 警告 kjtechforce - Kjtechforce mailman における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2164 2012-09-25 17:27 2009-06-22 Show GitHub Exploit DB Packet Storm
189449 7.5 危険 isabela gasparini - AdaptWeb の a_index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2152 2012-09-25 17:27 2009-06-22 Show GitHub Exploit DB Packet Storm
189450 4.3 警告 pantha - transLucid におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2145 2012-09-25 17:27 2009-06-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 25, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1781 - - - An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file. - CVE-2024-57408 2025-02-11 09:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1782 - - - Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vul… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2025-25194 2025-02-11 08:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1783 6.3 MEDIUM
Network
- - A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the a… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1158 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1784 - - - A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to… - CVE-2024-57177 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1785 - - - A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, in… - CVE-2024-46437 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1786 - - - Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service. - CVE-2024-46436 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1787 - - - A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. Thi… - CVE-2024-46435 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1788 - - - Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP … - CVE-2024-46434 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1789 - - - A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative pr… - CVE-2024-46433 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1790 - - - Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized ch… - CVE-2024-46432 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm