Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 18, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195071 4.3 警告 bloofox - BloofoxCMS の search.5.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4522 2012-06-26 16:19 2009-12-31 Show GitHub Exploit DB Packet Storm
195072 4.3 警告 Eclipse Foundation - BIRT の birt-viewer/run におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4521 2012-06-26 16:19 2009-12-17 Show GitHub Exploit DB Packet Storm
195073 3.5 注意 Drupal
astha bhatnagar
- Drupal のモジュールの OpenSocial Shindig-Integrator モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4514 2012-06-26 16:19 2009-12-31 Show GitHub Exploit DB Packet Storm
195074 9.3 危険 AzeoTech, Inc. - AzeoTech DAQFactory の Web サービスにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4480 2012-06-26 16:19 2009-12-30 Show GitHub Exploit DB Packet Storm
195075 4.3 警告 Episerver - Ektron CMS400.NET におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4473 2012-06-26 16:19 2009-12-30 Show GitHub Exploit DB Packet Storm
195076 7.5 危険 freeschool - FreeSchool における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4471 2012-06-26 16:18 2009-12-30 Show GitHub Exploit DB Packet Storm
195077 7.5 危険 dvbbs - DVBBS の boardrule.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4470 2012-06-26 16:18 2009-12-30 Show GitHub Exploit DB Packet Storm
195078 4.3 警告 giombetti - phpPowerCards の pagenumber.inc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4469 2012-06-26 16:18 2009-12-30 Show GitHub Exploit DB Packet Storm
195079 4.3 警告 deluxebb - DeluxeBB の misc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4468 2012-06-26 16:18 2009-12-30 Show GitHub Exploit DB Packet Storm
195080 4 警告 deluxebb - DeluxeBB の misc.php におけるアカウント登録される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4467 2012-06-26 16:18 2009-12-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
321 - - - OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the org… New CWE-287
CWE-284
CWE-285
CWE-269
CWE-272
Improper Authentication
Improper Access Control
Improper Authorization
 Improper Privilege Management
 Least Privilege Violation
CVE-2024-55954 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
322 - - - Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary… New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2024-36403 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
323 - - - Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download an… New CWE-287
Improper Authentication
CVE-2024-36402 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
324 - - - An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request. New - CVE-2024-57684 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
325 - - - Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creatin… New - CVE-2025-20630 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
326 - - - Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allo… New - CVE-2025-20621 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
327 - - - An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST req… New - CVE-2024-57683 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
328 - - - An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST req… New - CVE-2024-57682 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
329 - - - An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request. New - CVE-2024-57681 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
330 - - - An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST re… New - CVE-2024-57680 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm