Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 26, 2025, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194721 6.8 警告 Justin Ellison - Drupal 用の Node Gallery モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2305 2012-07-30 10:50 2012-05-2 Show GitHub Exploit DB Packet Storm
194722 5 警告 JanRain - Drupal 用の Janrain Engage モジュールにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2296 2012-07-30 10:48 2012-04-4 Show GitHub Exploit DB Packet Storm
194723 5 警告 Nancy Wichmann - Drupal 用の Site Documentation モジュールにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2302 2012-07-30 10:47 2012-04-25 Show GitHub Exploit DB Packet Storm
194724 2.1 注意 FindingScience - Apache 用 mod_auth_openid におけるセッション ID を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2760 2012-07-30 10:43 2012-07-25 Show GitHub Exploit DB Packet Storm
194725 4.3 警告 Emery Berger - Hoard の malloc および calloc 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-2676 2012-07-30 10:39 2012-06-10 Show GitHub Exploit DB Packet Storm
194726 4.3 警告 ned Productions - nedmalloc における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-2675 2012-07-30 10:33 2012-07-25 Show GitHub Exploit DB Packet Storm
194727 4.3 警告 Google - Android 用 Bionic の libc/bionic/malloc_debug_leak.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-2674 2012-07-30 10:32 2012-07-25 Show GitHub Exploit DB Packet Storm
194728 6.8 警告 eZ - eZ Publish の eZOE flash player におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-4053 2012-07-30 10:00 2012-07-8 Show GitHub Exploit DB Packet Storm
194729 4.3 警告 ノキア - Nokia PC Suite の Video Manager におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-2442 2012-07-30 09:58 2012-07-25 Show GitHub Exploit DB Packet Storm
194730 7.1 危険 アップル - Apple Safari 6.0 未満で使用される WebKit におけるサンドボックスの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3697 2012-07-27 14:28 2012-07-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 26, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
281 4.3 MEDIUM
Network
- - The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation o… New CWE-352
 Origin Validation Error
CVE-2024-13683 2025-01-24 16:15 2025-01-24 Show GitHub Exploit DB Packet Storm
282 6.5 MEDIUM
Network
- - The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to ins… New CWE-89
SQL Injection
CVE-2024-13680 2025-01-24 16:15 2025-01-24 Show GitHub Exploit DB Packet Storm
283 6.4 MEDIUM
Network
- - The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insufficient input saniti… New CWE-79
Cross-site Scripting
CVE-2024-13659 2025-01-24 15:15 2025-01-24 Show GitHub Exploit DB Packet Storm
284 - - - An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site sc… New CWE-79
Cross-site Scripting
CVE-2025-0314 2025-01-24 12:15 2025-01-24 Show GitHub Exploit DB Packet Storm
285 - - - An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have… New CWE-1220
 Insufficient Granularity of Access Control
CVE-2024-11931 2025-01-24 12:15 2025-01-24 Show GitHub Exploit DB Packet Storm
286 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Rejected Reason: This candidate is unused by its CNA. New - CVE-2021-30745 2025-01-24 11:15 2025-01-24 Show GitHub Exploit DB Packet Storm
287 - - - Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to … New - CVE-2024-53379 2025-01-24 08:15 2025-01-24 Show GitHub Exploit DB Packet Storm
288 - - - Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account. New - CVE-2025-0693 2025-01-24 07:15 2025-01-24 Show GitHub Exploit DB Packet Storm
289 - - - An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space. New - CVE-2024-55195 2025-01-24 07:15 2025-01-24 Show GitHub Exploit DB Packet Storm
290 - - - OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h. New - CVE-2024-55194 2025-01-24 07:15 2025-01-24 Show GitHub Exploit DB Packet Storm