Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 18, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
181 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Window…
Lightweight Directory Access Protocol (LDAP) クライアントのリモートでコードが実行される脆弱性 New CWE-362
競合状態
CVE-2024-49124 2025-01-17 14:41 2024-12-10 Show GitHub Exploit DB Packet Storm
182 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Window…
Microsoft Message Queuing (MSMQ) のリモートでコードが実行される脆弱性 New CWE-362
CWE-416
CVE-2024-49122 2025-01-17 14:37 2024-12-10 Show GitHub Exploit DB Packet Storm
183 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2025
Microso…
Windows ルーティングとリモート アクセス サービス (RRAS) のリモートでコードが実行される脆弱性 New CWE-122
CWE-noinfo
CVE-2024-49125 2025-01-17 14:32 2024-12-10 Show GitHub Exploit DB Packet Storm
184 9.8 緊急
Network
72crm Wukong CRM 72crm の Wukong CRM における信頼できないデータのデシリアライゼーションに関する脆弱性 New CWE-502
CWE-502
CVE-2024-23052 2025-01-17 14:28 2024-02-29 Show GitHub Exploit DB Packet Storm
185 6.1 警告
Network
Meow Apps ai engine Meow Apps の WordPress 用 ai engine におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-0378 2025-01-17 14:03 2024-03-2 Show GitHub Exploit DB Packet Storm
186 3.3
Local
IBM IBM TXSeries for Multiplatforms IBM の IBM TXSeries for Multiplatforms における脆弱性 New CWE-525
CWE-Other
CVE-2024-22343 2025-01-17 13:53 2024-05-9 Show GitHub Exploit DB Packet Storm
187 6.5 警告
Network
IBM IBM Aspera Faspex IBM の IBM Aspera Faspex におけるエンコードおよびエスケープに関する脆弱性 New CWE-116
CWE-644
CVE-2022-22399 2025-01-17 13:52 2022-07-28 Show GitHub Exploit DB Packet Storm
188 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 New CWE-401
有効期限後のメモリの解放の欠如
CVE-2021-47093 2025-01-17 13:45 2021-12-23 Show GitHub Exploit DB Packet Storm
189 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2023-52808 2025-01-17 13:45 2023-09-21 Show GitHub Exploit DB Packet Storm
190 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 New CWE-401
有効期限後のメモリの解放の欠如
CVE-2024-26829 2025-01-17 13:45 2024-02-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275231 - pingtel xpressa Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone. NVD-CWE-Other
CVE-2002-0675 2008-09-11 04:12 2002-07-23 Show GitHub Exploit DB Packet Storm
275232 - suse suse_linux ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are stored and executed in a file. NVD-CWE-Other
CVE-2002-0758 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275233 - suse suse_linux shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that … NVD-CWE-Other
CVE-2002-0762 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275234 - openbsd openssh
openbsd
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password. NVD-CWE-Other
CVE-2002-0765 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275235 - openbsd openbsd OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1,… NVD-CWE-Other
CVE-2002-0766 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275236 - ibm aix clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges. NVD-CWE-Other
CVE-2002-0790 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275237 - mozilla bugzilla Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi. NVD-CWE-Other
CVE-2002-0803 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275238 - mozilla bugzilla Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) fiel… NVD-CWE-Other
CVE-2002-0807 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275239 - mozilla bugzilla Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to bugl… NVD-CWE-Other
CVE-2002-0811 2008-09-11 04:12 2002-08-12 Show GitHub Exploit DB Packet Storm
275240 - mozilla bugzilla Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as… NVD-CWE-Other
CVE-2002-0008 2008-09-11 04:11 2002-01-31 Show GitHub Exploit DB Packet Storm