Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Nov. 16, 2024, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194101 6.8 警告 activecalendar - ActiveCalendar におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1111 2012-06-26 15:46 2007-02-26 Show GitHub Exploit DB Packet Storm
194102 5 警告 activecalendar - ActiveCalendar の data/showcode.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1110 2012-06-26 15:46 2007-02-26 Show GitHub Exploit DB Packet Storm
194103 6.8 警告 cs-gallery - Christian Schneider CS-Gallery の index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1108 2012-06-26 15:46 2007-02-26 Show GitHub Exploit DB Packet Storm
194104 7.5 危険 Coppermine Photo Gallery - CPG の thumbnails.php における SQL インジェクションの脆弱性 - CVE-2007-1107 2012-06-26 15:46 2007-02-26 Show GitHub Exploit DB Packet Storm
194105 5 警告 extreme phpbb - Extreme phpBB の functions.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1105 2012-06-26 15:46 2007-02-26 Show GitHub Exploit DB Packet Storm
194106 7.6 危険 Google - Google Desktop におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1085 2012-06-26 15:46 2007-02-22 Show GitHub Exploit DB Packet Storm
194107 7.1 危険 ftpx - FTP Explorer におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-1082 2012-06-26 15:46 2007-02-22 Show GitHub Exploit DB Packet Storm
194108 7.5 危険 flashgamescript - FlashGameScript の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-1078 2012-06-26 15:46 2007-02-22 Show GitHub Exploit DB Packet Storm
194109 7.5 危険 design4online - Design4Online UserPages の page.asp における SQL インジェクションの脆弱性 - CVE-2007-1077 2012-06-26 15:46 2007-02-22 Show GitHub Exploit DB Packet Storm
194110 9.3 危険 dji - NewsBin Pro におけるバッファオーバーフローの脆弱性 - CVE-2007-1074 2012-06-26 15:46 2007-02-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 16, 2024, 4:17 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2231 5.3 MEDIUM
Network
combodo itop Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displ… CWE-203
 Information Exposure Through Discrepancy
CVE-2024-51739 2024-11-9 00:56 2024-11-6 Show GitHub Exploit DB Packet Storm
2232 4.1 MEDIUM
Network
nvidia nvidia_container_toolkit
nvidia_gpu_operator
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name … NVD-CWE-Other
CVE-2024-0134 2024-11-9 00:53 2024-11-6 Show GitHub Exploit DB Packet Storm
2233 6.1 MEDIUM
Network
hashicorp consul A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and … CWE-79
Cross-site Scripting
CVE-2024-10086 2024-11-9 00:49 2024-10-31 Show GitHub Exploit DB Packet Storm
2234 10.0 CRITICAL
Network
webandprint ar Unrestricted Upload of File with Dangerous Type vulnerability in Web and Print Design AR For WordPress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-50496 2024-11-9 00:49 2024-10-29 Show GitHub Exploit DB Packet Storm
2235 4.3 MEDIUM
Network
hcltech connections HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entit… NVD-CWE-noinfo
CVE-2024-30106 2024-11-9 00:43 2024-10-29 Show GitHub Exploit DB Packet Storm
2236 6.1 MEDIUM
Network
elabftw elabftw eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show … CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2024-47826 2024-11-9 00:41 2024-10-15 Show GitHub Exploit DB Packet Storm
2237 7.5 HIGH
Network
vercel next.js Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a … CWE-674
 Uncontrolled Recursion
CVE-2024-47831 2024-11-9 00:39 2024-10-15 Show GitHub Exploit DB Packet Storm
2238 6.1 MEDIUM
Network
forgerock access_management An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under… CWE-601
Open Redirect
CVE-2024-25566 2024-11-9 00:38 2024-10-30 Show GitHub Exploit DB Packet Storm
2239 - - - The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to p… - CVE-2024-7982 2024-11-9 00:35 2024-11-8 Show GitHub Exploit DB Packet Storm
2240 5.5 MEDIUM
Local
gpac gpac GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so. NVD-CWE-noinfo
CVE-2023-37766 2024-11-9 00:35 2023-07-12 Show GitHub Exploit DB Packet Storm