Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 22, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191481 4.3 警告 jffnms - JFFNMS の auth.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3189 2012-09-25 16:47 2007-06-12 Show GitHub Exploit DB Packet Storm
191482 9.4 危険 ヒューレット・パッカード - HP Windows システムの Help および Support Center におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-3180 2012-09-25 16:47 2007-06-12 Show GitHub Exploit DB Packet Storm
191483 7.5 危険 particle blogger - Particle Blogger の archives.php における SQL インジェクションの脆弱性 - CVE-2007-3179 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191484 5 警告 ingate - Ingate Firewall などにおける SIP 認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2007-3177 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191485 4 警告 ingate - Ingate Firewall などにおける Support Report をダウンロードをされる脆弱性 - CVE-2007-3176 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191486 5.8 警告 マイクロソフト - Microsoft Internet Explorer 7 におけるフィッシング攻撃を実行される脆弱性 - CVE-2007-3164 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191487 7.5 危険 php real estate classifieds - PHP Real Estate Classifieds Premium Plus の admin/header.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3160 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191488 5 警告 miniweb http server - MiniWeb Http Server の http.c におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3159 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191489 5 警告 packeteer - Packeteer PacketShaper の Web management interface におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3151 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
191490 7.2 危険 MIT Kerberos
Todd C. Miller
- sudo における権限を取得される脆弱性 - CVE-2007-3149 2012-09-25 16:47 2007-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 22, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
651 6.1 MEDIUM
Network
- - The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing nonce validation on the wpabstracts_load_status()… CWE-352
 Origin Validation Error
CVE-2024-12385 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
652 4.4 MEDIUM
Network
- - The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping… CWE-79
Cross-site Scripting
CVE-2025-0554 2025-01-18 15:15 2025-01-18 Show GitHub Exploit DB Packet Storm
653 5.3 MEDIUM
Network
- - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, an… CWE-200
Information Exposure
CVE-2025-0318 2025-01-18 15:15 2025-01-18 Show GitHub Exploit DB Packet Storm
654 7.5 HIGH
Network
- - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parame… CWE-89
SQL Injection
CVE-2025-0308 2025-01-18 15:15 2025-01-18 Show GitHub Exploit DB Packet Storm
655 6.1 MEDIUM
Network
- - The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.5 due to insufficient input saniti… CWE-79
Cross-site Scripting
CVE-2024-13516 2025-01-18 15:15 2025-01-18 Show GitHub Exploit DB Packet Storm
656 6.1 MEDIUM
Network
- - The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'path' parameter in all versions up to, and including, 2.2… CWE-79
Cross-site Scripting
CVE-2024-13515 2025-01-18 15:15 2025-01-18 Show GitHub Exploit DB Packet Storm
657 5.3 MEDIUM
Network
- - The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete… CWE-862
 Missing Authorization
CVE-2024-12071 2025-01-18 13:15 2025-01-18 Show GitHub Exploit DB Packet Storm
658 - - - Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where yo… CWE-94
Code Injection
CVE-2025-23209 2025-01-18 10:15 2025-01-18 Show GitHub Exploit DB Packet Storm
659 - - - Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3 - CVE-2024-11923 2025-01-18 09:15 2025-01-18 Show GitHub Exploit DB Packet Storm
660 - - - A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code. - CVE-2023-50739 2025-01-18 09:15 2025-01-18 Show GitHub Exploit DB Packet Storm