Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 31, 2024, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189591 10 危険 Foxit Software Inc - Foxit Reader におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0837 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
189592 10 危険 Foxit Software Inc - Foxit Reader における任意のプログラムを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-0836 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
189593 7.5 危険 PHP-Fusion
ausimods
- PHP-Fusion の E-Cart モジュールの items.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0832 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189594 4.3 警告 andrew freed - QuoteBook におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0830 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189595 7.5 危険 andrew freed - QuoteBook における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0829 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189596 5 警告 freedville - QuoteBook におけるユーザの資格情報を含むデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0828 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189597 5 警告 freedville - PollHelper におけるユーザの資格情報を含むデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0827 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189598 5 警告 freedville - BlogHelper におけるユーザの資格情報を含むデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0826 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
189599 4.3 警告 blogsa - Widgets.aspx におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0814 2012-06-26 16:10 2009-03-4 Show GitHub Exploit DB Packet Storm
189600 9.3 危険 bpsoft - BreakPoint Software Hex Workshop におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0812 2012-06-26 16:10 2009-03-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 1, 2024, 6:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201 - - - Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attack… New CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2024-10454 2024-10-31 22:15 2024-10-31 Show GitHub Exploit DB Packet Storm
202 9.8 CRITICAL
Network
tareqhasan meetup Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1. New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-50483 2024-10-31 22:12 2024-10-28 Show GitHub Exploit DB Packet Storm
203 9.8 CRITICAL
Network
mansurahamed woocommerce_quote_calculator Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocomme… New CWE-89
SQL Injection
CVE-2024-50479 2024-10-31 22:02 2024-10-28 Show GitHub Exploit DB Packet Storm
204 9.8 CRITICAL
Network
codezips hospital_appointment_system A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument U… New CWE-89
SQL Injection
CVE-2024-10449 2024-10-31 21:47 2024-10-29 Show GitHub Exploit DB Packet Storm
205 9.8 CRITICAL
Network
pymumu smartdns SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request. Update CWE-787
 Out-of-bounds Write
CVE-2023-31470 2024-10-31 21:47 2023-04-29 Show GitHub Exploit DB Packet Storm
206 9.0 CRITICAL
Network
apache
intel
cvat
siemens
debian
sonicwall
fedoraproject
log4j
oneapi
audio_development_kit
datacenter_manager
system_debugger
secure_device_onboard
sensor_solution_firmware_development_kit
genomics_kernel_library
system_studio
c…
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC)… Update CWE-917
 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2021-45046 2024-10-31 21:17 2021-12-15 Show GitHub Exploit DB Packet Storm
207 6.1 MEDIUM
Network
rextheme wp_vr The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Store… Update CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2023-6529 2024-10-31 20:45 2024-01-9 Show GitHub Exploit DB Packet Storm
208 4.3 MEDIUM
Network
rextheme wp_vr The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitr… Update CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2023-1414 2024-10-31 20:45 2023-04-25 Show GitHub Exploit DB Packet Storm
209 6.1 MEDIUM
Network
rextheme wp_vr The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against h… Update - CVE-2023-1413 2024-10-31 20:45 2023-04-17 Show GitHub Exploit DB Packet Storm
210 8.8 HIGH
Network
rextheme wp_vr Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions. Update CWE-352
 Origin Validation Error
CVE-2023-25708 2024-10-31 20:45 2023-03-15 Show GitHub Exploit DB Packet Storm