Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
192931 4.1 警告 マカフィー - McAfee Virex における任意のファイルのスキャンをスキップするよう Virex を再設定される脆弱性 - CVE-2007-1226 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192932 5 警告 日立 - Hitachi OSAS/FT/W におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-1223 2012-09-25 16:47 2007-02-23 Show GitHub Exploit DB Packet Storm
192933 7.2 危険 Parallels - Mac 用の Parrallels Desktop におけるホストファイルシステムへファイルを書き込まれる脆弱性 - CVE-2007-1222 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192934 7.2 危険 マイクロソフト - Microsoft Xbox 360 カーネルにおけるハイパーバイザーシステムコールを強制的に実行される脆弱性 - CVE-2007-1221 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192935 6.2 警告 マイクロソフト - Microsoft Xbox 360 カーネルの Hypervisor における任意のコードを実行される脆弱性 - CVE-2007-1220 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192936 2.1 注意 Norman - Norman SandBox Analyzer におけるローカルマシンがエミュレータであることを確認される脆弱性 CWE-200
情報漏えい
CVE-2007-1194 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192937 9.3 危険 OrangeHRM - OrangeHRM の Login ページにおける脆弱性 - CVE-2007-1193 2012-09-25 16:47 2007-02-9 Show GitHub Exploit DB Packet Storm
192938 5 警告 hyperbook - Thomas R. Pasawicz HyperBook Guestbook におけるパスワードハッシュをダウンロードされる脆弱性 - CVE-2007-1192 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192939 6.4 警告 nukescripts - NukeSentinel の nukesentinel.php における SQL インジェクションの脆弱性 - CVE-2007-1172 2012-09-25 16:47 2007-03-2 Show GitHub Exploit DB Packet Storm
192940 6.8 警告 Mozilla Foundation - Mozilla Firefox におけるアドレスバーなどを偽造される脆弱性 - CVE-2007-1256 2012-09-25 16:47 2007-03-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 2, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
851 5.3 MEDIUM
Network
- - IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that c… CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2023-38013 2025-01-25 23:15 2025-01-25 Show GitHub Exploit DB Packet Storm
852 5.3 MEDIUM
Network
- - IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially… CWE-22
Path Traversal
CVE-2023-38012 2025-01-25 23:15 2025-01-25 Show GitHub Exploit DB Packet Storm
853 7.5 HIGH
Network
- - The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads dire… CWE-200
Information Exposure
CVE-2024-13562 2025-01-25 21:15 2025-01-25 Show GitHub Exploit DB Packet Storm
854 6.4 MEDIUM
Network
- - The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all ver… CWE-79
Cross-site Scripting
CVE-2025-0350 2025-01-25 19:15 2025-01-25 Show GitHub Exploit DB Packet Storm
855 3.8 LOW
Network
- - The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-13450 2025-01-25 18:15 2025-01-25 Show GitHub Exploit DB Packet Storm
856 5.3 MEDIUM
Network
- - The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and including, 2.2.1. … CWE-862
 Missing Authorization
CVE-2024-13449 2025-01-25 18:15 2025-01-25 Show GitHub Exploit DB Packet Storm
857 6.4 MEDIUM
Network
- - The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output… CWE-79
Cross-site Scripting
CVE-2024-13599 2025-01-25 17:15 2025-01-25 Show GitHub Exploit DB Packet Storm
858 6.4 MEDIUM
Network
- - The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' shortcode in all versions up to, and including, 1.7 due to insufficient input s… CWE-79
Cross-site Scripting
CVE-2024-13586 2025-01-25 17:15 2025-01-25 Show GitHub Exploit DB Packet Storm
859 6.4 MEDIUM
Network
- - The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in all versions up to, and including, 6.1.3 due to insufficient input sanitizatio… CWE-79
Cross-site Scripting
CVE-2024-13551 2025-01-25 17:15 2025-01-25 Show GitHub Exploit DB Packet Storm
860 6.5 MEDIUM
Network
- - The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the 'abcjs' shortcode. This makes it possible for authent… CWE-22
Path Traversal
CVE-2024-13550 2025-01-25 17:15 2025-01-25 Show GitHub Exploit DB Packet Storm