Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 23, 2025, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190071 4.3 警告 Free Document Management Software - OpenDocMan の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2788 2012-09-25 17:17 2008-06-20 Show GitHub Exploit DB Packet Storm
190072 4.3 警告 Free Document Management Software - OpenDocMan の out.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2787 2012-09-25 17:17 2008-06-20 Show GitHub Exploit DB Packet Storm
190073 10 危険 Mozilla Foundation - Firefox におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2786 2012-09-25 17:17 2008-06-19 Show GitHub Exploit DB Packet Storm
190074 4.3 警告 Horde - Horde Groupware などの製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2783 2012-09-25 17:17 2008-06-19 Show GitHub Exploit DB Packet Storm
190075 7.5 危険 otomigenx - OtomiGenX におけるディレクトリトラバーサルの脆弱性 CWE-200
CWE-22
CVE-2008-2782 2012-09-25 17:17 2008-06-19 Show GitHub Exploit DB Packet Storm
190076 4.3 警告 luca corbo - Ortro におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2777 2012-09-25 17:17 2008-06-19 Show GitHub Exploit DB Packet Storm
190077 7.5 危険 mycrocms - MycroCMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2770 2012-09-25 17:17 2008-06-18 Show GitHub Exploit DB Packet Storm
190078 7.5 危険 jamm-media - JAMM CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2755 2012-09-25 17:17 2008-06-18 Show GitHub Exploit DB Packet Storm
190079 7.5 危険 paridel - PSB における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2753 2012-09-25 17:17 2008-06-18 Show GitHub Exploit DB Packet Storm
190080 7.1 危険 マイクロソフト - Microsoft Word 2000 などにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-2752 2012-09-25 17:17 2008-06-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 23, 2025, 5:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
631 4.4 MEDIUM
Network
- - IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials. CWE-1323
CVE-2024-49338 2025-01-19 00:15 2025-01-19 Show GitHub Exploit DB Packet Storm
632 2.4 LOW
Network
- - A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the compone… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0559 2025-01-18 23:15 2025-01-18 Show GitHub Exploit DB Packet Storm
633 6.3 MEDIUM
Network
- - A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/re… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0558 2025-01-18 22:15 2025-01-18 Show GitHub Exploit DB Packet Storm
634 4.3 MEDIUM
Network
- - A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the co… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0557 2025-01-18 18:15 2025-01-18 Show GitHub Exploit DB Packet Storm
635 9.8 CRITICAL
Network
- - The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a use… CWE-620
 Unverified Password Change
CVE-2024-13375 2025-01-18 18:15 2025-01-18 Show GitHub Exploit DB Packet Storm
636 7.5 HIGH
Network
- - The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insuf… CWE-89
SQL Injection
CVE-2024-13184 2025-01-18 18:15 2025-01-18 Show GitHub Exploit DB Packet Storm
637 - - - A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation o… - CVE-2025-0538 2025-01-18 18:15 2025-01-18 Show GitHub Exploit DB Packet Storm
638 - - - A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php.… - CVE-2025-0537 2025-01-18 18:15 2025-01-18 Show GitHub Exploit DB Packet Storm
639 6.4 MEDIUM
Network
- - The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to… CWE-79
Cross-site Scripting
CVE-2024-13392 2025-01-18 17:15 2025-01-18 Show GitHub Exploit DB Packet Storm
640 4.3 MEDIUM
Network
- - The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing ca… CWE-862
 Missing Authorization
CVE-2025-0515 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm