Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1941 7.2 重要
Network
BeyondTrust Corporation remote support
privileged remote access
BeyondTrust Corporation の privileged remote access および remote support における OS コマンドインジェクションの脆弱性 CWE-78
CWE-78
CVE-2024-12686 2025-01-15 15:01 2024-12-18 Show GitHub Exploit DB Packet Storm
1942 7.5 重要
Network
クアルコム snapdragon auto 5g modem-rf ファームウェア
wcn3980 ファームウェア
c-v2x 9150 ファームウェア
WSA8810 ファームウェア
WCN3950 ファームウェア
QCS610 ファームウェア
QCS410 フ…
複数のクアルコム製品における脆弱性 CWE-20
CWE-noinfo
CVE-2024-21453 2025-01-15 15:01 2024-04-1 Show GitHub Exploit DB Packet Storm
1943 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2024-29231 2025-01-15 15:01 2024-03-28 Show GitHub Exploit DB Packet Storm
1944 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29234 2025-01-15 15:00 2024-03-28 Show GitHub Exploit DB Packet Storm
1945 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29236 2025-01-15 15:00 2024-03-28 Show GitHub Exploit DB Packet Storm
1946 7.8 重要
Local
クアルコム QCA1062 ファームウェア
QCA2064 ファームウェア
fastconnect 6900 ファームウェア
QCA6595AU ファームウェア
qcc2076 ファームウェア
AQT1000 ファームウェア
QCA1064 ファームウェア
QCA2066 ファ…
複数のクアルコム製品における境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-45542 2025-01-15 15:00 2024-09-2 Show GitHub Exploit DB Packet Storm
1947 4.7 警告
Local
Huawei HarmonyOS Huawei の HarmonyOS における競合状態に関する脆弱性 CWE-362
CWE-362
CVE-2024-54122 2025-01-15 15:00 2024-12-12 Show GitHub Exploit DB Packet Storm
1948 7.5 重要
Network
Huawei HarmonyOS Huawei の HarmonyOS における脆弱性 CWE-200
CWE-noinfo
CVE-2024-56435 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
1949 7.5 重要
Network
Huawei EMUI
HarmonyOS
Huawei の EMUI および HarmonyOS における脆弱性 CWE-94
CWE-Other
CVE-2024-56448 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
1950 7.5 重要
Network
Huawei EMUI
HarmonyOS
Huawei の EMUI および HarmonyOS における脆弱性 CWE-840
CWE-noinfo
CVE-2024-56449 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 19, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
41 - - - A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functi… New - CVE-2025-1023 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
42 - - - A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This … New - CVE-2025-0981 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
43 6.5 MEDIUM
Network
- - The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insuffici… New CWE-89
SQL Injection
CVE-2024-13369 2025-02-18 19:15 2025-02-18 Show GitHub Exploit DB Packet Storm
44 4.3 MEDIUM
Network
- - The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due … New CWE-352
 Origin Validation Error
CVE-2024-13718 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
45 6.4 MEDIUM
Network
- - The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitiza… New CWE-79
Cross-site Scripting
CVE-2024-13395 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
46 5.3 MEDIUM
Network
- - The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability… New CWE-862
 Missing Authorization
CVE-2024-13316 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
47 9.8 CRITICAL
Network
- - The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plug… New CWE-620
 Unverified Password Change
CVE-2024-12860 2025-02-18 18:15 2025-02-18 Show GitHub Exploit DB Packet Storm
48 6.1 MEDIUM
Network
- - The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up… New CWE-79
Cross-site Scripting
CVE-2025-0864 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm
49 - - - Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as th… New - CVE-2025-0425 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm
50 - - - In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able … New - CVE-2025-0424 2025-02-18 17:15 2025-02-18 Show GitHub Exploit DB Packet Storm