Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 20, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191341 7.5 危険 php firstpost - PhpFirstPost の block.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2665 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
191342 3.5 注意 MySQL AB - MySQL におけるパーティションで区切られたテーブルから重要な情報を取得される脆弱性 - CVE-2007-2693 2012-09-25 16:47 2006-10-26 Show GitHub Exploit DB Packet Storm
191343 7.8 危険 idautomation - IDAutomationLinear6.dll の ID Automation Linear Barcode ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2658 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
191344 7.8 危険 ヒューレット・パッカード - hpqvwocx.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2656 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
191345 7.5 危険 Netwin Ltd - SurgeMail の NetWin Webmail におけるリモートコードを実行される脆弱性 CWE-134
書式文字列の問題
CVE-2007-2655 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
191346 6.5 警告 monalbum - Monalbum の admin/admin_configuration.php における PHP コードを挿入される脆弱性 - CVE-2007-2647 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
191347 9.4 危険 morovia - Morovia Barcode ActiveX Professional における任意のファイルを上書きされる脆弱性 - CVE-2007-2644 2012-09-25 16:47 2007-05-13 Show GitHub Exploit DB Packet Storm
191348 7.8 危険 heiko stamer - LibTMCG におけるプライベートカードに関する重要な情報を取得される脆弱性 - CVE-2007-2640 2012-09-25 16:47 2007-05-13 Show GitHub Exploit DB Packet Storm
191349 5 警告 MoinMoin - MoinMoin における特定のページを読まれる脆弱性 - CVE-2007-2637 2012-09-25 16:47 2007-05-13 Show GitHub Exploit DB Packet Storm
191350 6.8 警告 jason frisvold - phpTodo における脆弱性 - CVE-2007-2636 2012-09-25 16:47 2007-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 20, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
631 - - - SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. - CVE-2025-22976 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
632 - - - SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter. - CVE-2025-22964 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
633 6.1 MEDIUM
Network
- - The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and includin… CWE-79
Cross-site Scripting
CVE-2025-0215 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
634 - - - An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or H… - CVE-2024-41454 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
635 - - - Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command. - CVE-2024-39967 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
636 - - - An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclo… - CVE-2025-0107 2025-01-16 08:15 2025-01-11 Show GitHub Exploit DB Packet Storm
637 - - - A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer derefer… CWE-476
CWE-404
 NULL Pointer Dereference
 Improper Resource Shutdown or Release
CVE-2025-0492 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
638 - - - A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of the argument id l… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0491 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
639 - - - An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. - CVE-2024-36751 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
640 - - - A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /fladmin/cat_edit.php. The manipulation of t… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0487 2025-01-16 06:15 2025-01-16 Show GitHub Exploit DB Packet Storm