Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
181 6.1 警告
Network
Liferay Digital Experience Platform Liferay の Digital Experience Platform におけるオープンリダイレクトの脆弱性 New CWE-601
CWE-601
CVE-2023-44308 2025-01-30 10:31 2023-09-28 Show GitHub Exploit DB Packet Storm
182 5.4 警告
Network
WordPress Go Go Custom Field Template WordPress Go Go の WordPress 用 Custom Field Template におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2023-6745 2025-01-30 10:31 2023-12-12 Show GitHub Exploit DB Packet Storm
183 7.8 重要
Local
- IBM の Security Verify Access における脆弱性 New CWE-250
CWE-Other
CVE-2024-49804 2025-01-30 10:24 2024-11-29 Show GitHub Exploit DB Packet Storm
184 7.8 重要
Local
IBM Security Verify Access Docker IBM の Security Verify Access Docker における脆弱性 New CWE-250
CWE-Other
CVE-2024-35141 2025-01-30 10:17 2024-05-30 Show GitHub Exploit DB Packet Storm
185 5.4 警告
Network
POSIMYTH The Plus Addons for Elementor Page Builder POSIMYTH の WordPress 用 The Plus Addons for Elementor Page Builder におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-5341 2025-01-30 10:10 2024-05-30 Show GitHub Exploit DB Packet Storm
186 7.5 重要
Network
Mikko Saari Relevanssi Mikko Saari の WordPress 用 Relevanssi における脆弱性 New CWE-200
CWE-noinfo
CVE-2024-7630 2025-01-30 10:10 2024-08-16 Show GitHub Exploit DB Packet Storm
187 5.4 警告
Network
bdthemes element pack bdthemes の WordPress 用 element pack におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-9058 2025-01-30 10:10 2024-12-3 Show GitHub Exploit DB Packet Storm
188 6.1 警告
Network
3dflipbook 3d flipbook 3dflipbook の WordPress 用 3d flipbook におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-43152 2025-01-30 10:10 2024-08-12 Show GitHub Exploit DB Packet Storm
189 9.8 緊急
Network
OpenImageIO project OpenImageIO OpenImageIO project の OpenImageIO における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-55192 2025-01-30 10:10 2024-12-6 Show GitHub Exploit DB Packet Storm
190 6.5 警告
Network
インターネット技術タスクフォース (IETF) IPv6 インターネット技術タスクフォース (IETF) の IPv6 における脆弱性 New CWE-940
CWE-Other
CVE-2025-23018 2025-01-30 10:10 2025-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 1, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
551 - - - The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used agai… - CVE-2024-12723 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
552 - - - A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows… - CVE-2025-23084 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
553 - - - Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed. - CVE-2025-22865 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
554 - - - A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in… - CVE-2024-45341 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
555 - - - Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless othe… - CVE-2024-45340 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
556 - - - When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its… - CVE-2024-45339 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
557 - - - The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that h… - CVE-2024-45336 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
558 - - - Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be … - CVE-2022-3365 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
559 - - - A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privile… - CVE-2025-24176 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm
560 - - - The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences. - CVE-2025-24174 2025-01-29 01:15 2025-01-28 Show GitHub Exploit DB Packet Storm