Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189741 5 警告 Ignite Realtime - Ignite Realtime Openfire の log.jsp におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0497 2012-09-25 17:27 2009-02-9 Show GitHub Exploit DB Packet Storm
189742 7.5 危険 it747 - REALTOR 747 の include/define.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0495 2012-09-25 17:27 2009-02-9 Show GitHub Exploit DB Packet Storm
189743 7.5 危険 mivaco - Joomla! 用の Portfol コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0494 2012-09-25 17:27 2009-02-9 Show GitHub Exploit DB Packet Storm
189744 7.5 危険 martin unzner - IT!CMS の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0493 2012-09-25 17:27 2009-02-9 Show GitHub Exploit DB Packet Storm
189745 4.3 警告 Phorum - Phorum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0488 2012-09-25 17:27 2009-01-25 Show GitHub Exploit DB Packet Storm
189746 4.3 警告 Mahara - Mahara におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0487 2012-09-25 17:27 2009-01-28 Show GitHub Exploit DB Packet Storm
189747 7.5 危険 onlinegrades - Online Grades の admin/admin_login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0479 2012-09-25 17:27 2009-02-5 Show GitHub Exploit DB Packet Storm
189748 9.3 危険 multimediasoft - MultiMedia Soft audio コンポーネントにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0476 2012-09-25 17:27 2009-02-8 Show GitHub Exploit DB Packet Storm
189749 7.5 危険 magtrb - AJA Portal におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0457 2012-09-25 17:27 2009-02-10 Show GitHub Exploit DB Packet Storm
189750 5 警告 onlinegrades - Online Grades における設定情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-0453 2012-09-25 17:27 2009-02-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 24, 2025, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1681 6.3 MEDIUM
Network
- - A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the a… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1158 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1682 - - - A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to… - CVE-2024-57177 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1683 - - - A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, in… - CVE-2024-46437 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1684 - - - Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service. - CVE-2024-46436 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1685 - - - A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. Thi… - CVE-2024-46435 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1686 - - - Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP … - CVE-2024-46434 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1687 - - - A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative pr… - CVE-2024-46433 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1688 - - - Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized ch… - CVE-2024-46432 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1689 - - - Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic… - CVE-2024-46431 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1690 - - - Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator… - CVE-2024-46430 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm