Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1941 7.2 重要
Network
BeyondTrust Corporation remote support
privileged remote access
BeyondTrust Corporation の privileged remote access および remote support における OS コマンドインジェクションの脆弱性 CWE-78
CWE-78
CVE-2024-12686 2025-01-15 15:01 2024-12-18 Show GitHub Exploit DB Packet Storm
1942 7.5 重要
Network
クアルコム snapdragon auto 5g modem-rf ファームウェア
wcn3980 ファームウェア
c-v2x 9150 ファームウェア
WSA8810 ファームウェア
WCN3950 ファームウェア
QCS610 ファームウェア
QCS410 フ…
複数のクアルコム製品における脆弱性 CWE-20
CWE-noinfo
CVE-2024-21453 2025-01-15 15:01 2024-04-1 Show GitHub Exploit DB Packet Storm
1943 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における配列インデックスの検証に関する脆弱性 CWE-129
配列インデックスの不適切な検証
CVE-2024-29231 2025-01-15 15:01 2024-03-28 Show GitHub Exploit DB Packet Storm
1944 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29234 2025-01-15 15:00 2024-03-28 Show GitHub Exploit DB Packet Storm
1945 8.8 重要
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29236 2025-01-15 15:00 2024-03-28 Show GitHub Exploit DB Packet Storm
1946 7.8 重要
Local
クアルコム QCA1062 ファームウェア
QCA2064 ファームウェア
fastconnect 6900 ファームウェア
QCA6595AU ファームウェア
qcc2076 ファームウェア
AQT1000 ファームウェア
QCA1064 ファームウェア
QCA2066 ファ…
複数のクアルコム製品における境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-45542 2025-01-15 15:00 2024-09-2 Show GitHub Exploit DB Packet Storm
1947 4.7 警告
Local
Huawei HarmonyOS Huawei の HarmonyOS における競合状態に関する脆弱性 CWE-362
CWE-362
CVE-2024-54122 2025-01-15 15:00 2024-12-12 Show GitHub Exploit DB Packet Storm
1948 7.5 重要
Network
Huawei HarmonyOS Huawei の HarmonyOS における脆弱性 CWE-200
CWE-noinfo
CVE-2024-56435 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
1949 7.5 重要
Network
Huawei EMUI
HarmonyOS
Huawei の EMUI および HarmonyOS における脆弱性 CWE-94
CWE-Other
CVE-2024-56448 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
1950 7.5 重要
Network
Huawei EMUI
HarmonyOS
Huawei の EMUI および HarmonyOS における脆弱性 CWE-840
CWE-noinfo
CVE-2024-56449 2025-01-15 15:00 2024-12-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 22, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
71 6.4 MEDIUM
Network
- - The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all v… New CWE-79
Cross-site Scripting
CVE-2024-13461 2025-02-21 19:15 2025-02-21 Show GitHub Exploit DB Packet Storm
72 8.8 HIGH
Network
- - The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via s… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2024-13353 2025-02-21 19:15 2025-02-21 Show GitHub Exploit DB Packet Storm
73 6.4 MEDIUM
Network
- - The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization… New CWE-79
Cross-site Scripting
CVE-2024-12452 2025-02-21 19:15 2025-02-21 Show GitHub Exploit DB Packet Storm
74 5.3 MEDIUM
Network
- - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in al… New CWE-89
SQL Injection
CVE-2024-12276 2025-02-21 19:15 2025-02-21 Show GitHub Exploit DB Packet Storm
75 6.4 MEDIUM
Network
- - The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's piecal shortcode in all versions up to, and including, 1.2.5 due to i… New CWE-79
Cross-site Scripting
CVE-2025-1410 2025-02-21 18:15 2025-02-21 Show GitHub Exploit DB Packet Storm
76 - - - In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by sp… New - CVE-2025-0728 2025-02-21 18:15 2025-02-21 Show GitHub Exploit DB Packet Storm
77 - - - In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by sp… New - CVE-2025-0727 2025-02-21 18:15 2025-02-21 Show GitHub Exploit DB Packet Storm
78 - - - In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a fi… New - CVE-2025-0726 2025-02-21 17:15 2025-02-21 Show GitHub Exploit DB Packet Storm
79 - - - The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting att… New - CVE-2024-13585 2025-02-21 15:15 2025-02-21 Show GitHub Exploit DB Packet Storm
80 - - - The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C… New - CVE-2024-13314 2025-02-21 15:15 2025-02-21 Show GitHub Exploit DB Packet Storm