Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191541 4.3 警告 makale scripti - Makale Scripti におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6673 2012-09-25 16:59 2008-01-8 Show GitHub Exploit DB Packet Storm
191542 7.5 危険 instantsoftwares - Instant Softwares Dating Site の login_form.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6671 2012-09-25 16:59 2008-01-8 Show GitHub Exploit DB Packet Storm
191543 7.5 危険 peergoal - MCZ の admin/uploadgames.php における無制限にファイルをアップロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6668 2012-09-25 16:59 2008-01-7 Show GitHub Exploit DB Packet Storm
191544 6.8 警告 myphp - MyPHP Forum の faq.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6667 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191545 7.5 危険 netchemia - Netchemia oneSCHOOL の admin/login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6665 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191546 7.5 危険 mihalism - Mihalism Multi Forum Host の source/includes/load_forum.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6657 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191547 7.5 危険 matpo bilder galerie - Kontakt Formular における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6655 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191548 9.3 危険 macrovision - Macrovision の InstallShield Update Service Web Agent におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6654 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191549 5 警告 mihalism - Mihalism Multi Host の download.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6653 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
191550 7.5 危険 matpo bilder galerie - MatPo Bilder Galerie における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6649 2012-09-25 16:59 2008-01-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 31, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
851 7.5 HIGH
Network
- - The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 … CWE-22
Path Traversal
CVE-2024-13409 2025-01-24 20:15 2025-01-24 Show GitHub Exploit DB Packet Storm
852 6.4 MEDIUM
Network
- - The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_sgwf' shortcode in all versions up to, and including, 2.0 due to insufficient i… CWE-79
Cross-site Scripting
CVE-2024-13583 2025-01-24 19:15 2025-01-24 Show GitHub Exploit DB Packet Storm
853 6.4 MEDIUM
Network
- - The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient in… CWE-79
Cross-site Scripting
CVE-2024-12494 2025-01-24 19:15 2025-01-24 Show GitHub Exploit DB Packet Storm
854 9.8 CRITICAL
Network
- - The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attacke… CWE-22
Path Traversal
CVE-2024-13545 2025-01-24 18:15 2025-01-24 Show GitHub Exploit DB Packet Storm
855 4.3 MEDIUM
Network
- - The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation o… CWE-352
 Origin Validation Error
CVE-2024-13683 2025-01-24 16:15 2025-01-24 Show GitHub Exploit DB Packet Storm
856 6.5 MEDIUM
Network
- - The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to ins… CWE-89
SQL Injection
CVE-2024-13680 2025-01-24 16:15 2025-01-24 Show GitHub Exploit DB Packet Storm
857 6.4 MEDIUM
Network
- - The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insufficient input saniti… CWE-79
Cross-site Scripting
CVE-2024-13659 2025-01-24 15:15 2025-01-24 Show GitHub Exploit DB Packet Storm
858 - - - An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site sc… CWE-79
Cross-site Scripting
CVE-2025-0314 2025-01-24 12:15 2025-01-24 Show GitHub Exploit DB Packet Storm
859 - - - An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have… CWE-1220
 Insufficient Granularity of Access Control
CVE-2024-11931 2025-01-24 12:15 2025-01-24 Show GitHub Exploit DB Packet Storm
860 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Rejected Reason: This candidate is unused by its CNA. - CVE-2021-30745 2025-01-24 11:15 2025-01-24 Show GitHub Exploit DB Packet Storm