Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190061 7.8 危険 interface-medien - Interface Medien ibase の download.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6288 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190062 6.5 警告 ortus.nirn - CMS Ortus の engine/users/users_edit_pub.inc における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6282 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190063 6.8 警告 mjcreation - FamilyProject の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6274 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190064 6 警告 myktools - MyKtools の configuration_script.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6273 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190065 7.5 危険 miticdjd - Dragan Mitic Apoll の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6272 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190066 7.5 危険 miticdjd - Dragan Mitic Apoll の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6270 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190067 7.5 危険 joovili - Joovili における管理者を含むユーザ権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-6269 2012-09-25 17:27 2009-02-25 Show GitHub Exploit DB Packet Storm
190068 7.5 危険 infireal - SaturnCMS の lib/user/t_user.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6263 2012-09-25 17:27 2009-02-24 Show GitHub Exploit DB Packet Storm
190069 7.5 危険 infireal - SaturnCMS の lib/url/meta_url.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6262 2012-09-25 17:27 2009-02-24 Show GitHub Exploit DB Packet Storm
190070 7.5 危険 openasp - Openasp の default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6257 2012-09-25 17:27 2009-02-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1361 - - - Missing Authorization vulnerability in Revmakx WP Duplicate – WordPress Migration Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Duplicate – Wor… CWE-862
 Missing Authorization
CVE-2025-24652 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1362 - - - Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-24650 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1363 - - - Missing Authorization vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhanceme… CWE-862
 Missing Authorization
CVE-2025-24649 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1364 - - - Cross-Site Request Forgery (CSRF) vulnerability in datafeedr.com WooCommerce Cloak Affiliate Links allows Cross Site Request Forgery. This issue affects WooCommerce Cloak Affiliate Links: from n/a th… CWE-352
 Origin Validation Error
CVE-2025-24647 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1365 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stor… CWE-79
Cross-site Scripting
CVE-2025-24644 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1366 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pete Dring Create with Code allows DOM-Based XSS. This issue affects Create with Code: from n/a t… CWE-79
Cross-site Scripting
CVE-2025-24638 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1367 - - - Cross-Site Request Forgery (CSRF) vulnerability in Laymance Technologies LLC MachForm Shortcode allows Stored XSS. This issue affects MachForm Shortcode: from n/a through 1.4.1. CWE-352
 Origin Validation Error
CVE-2025-24636 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1368 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Orbisius Simple Notice allows Stored XSS. This issue affects Orbisius S… CWE-79
Cross-site Scripting
CVE-2025-24634 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1369 - - - Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Build Private S… CWE-862
 Missing Authorization
CVE-2025-24633 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1370 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford, LinSoftware Blur Text allows Stored XSS. This issue affects Blur Text: from n/a t… CWE-79
Cross-site Scripting
CVE-2025-24627 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm