Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195441 5 警告 The PHP Group
サイボウズ
オラクル
- PHP におけるサービス運用妨害 (CPU 資源の消費) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-4885 2012-07-20 17:18 2011-12-28 Show GitHub Exploit DB Packet Storm
195442 4.3 警告 オラクル - Oracle Solaris における Network/NFS の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3131 2012-07-20 16:17 2012-07-17 Show GitHub Exploit DB Packet Storm
195443 4.3 警告 オラクル - Oracle Solaris における pkg.depotd に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3130 2012-07-20 16:16 2012-07-17 Show GitHub Exploit DB Packet Storm
195444 5.1 警告 オラクル - Oracle Solaris における Gnome PDF viewer の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3129 2012-07-20 16:14 2012-07-17 Show GitHub Exploit DB Packet Storm
195445 3.7 注意 オラクル - Oracle SPARC T シリーズサーバのファームウェアにおける Integrated Lights Out Manager の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3128 2012-07-20 16:13 2012-07-17 Show GitHub Exploit DB Packet Storm
195446 5.4 警告 オラクル - Oracle Solaris における SCTP の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3127 2012-07-20 16:11 2012-07-17 Show GitHub Exploit DB Packet Storm
195447 6.2 警告 オラクル - Oracle Solaris Cluster における Apache Tomcat Agent の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3126 2012-07-20 16:10 2012-07-17 Show GitHub Exploit DB Packet Storm
195448 7.1 危険 オラクル - Oracle Solaris における TCP/IP の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3125 2012-07-20 16:09 2012-07-17 Show GitHub Exploit DB Packet Storm
195449 5 警告 オラクル - Oracle Solaris における Kernel/KSSL の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3124 2012-07-20 16:07 2012-07-17 Show GitHub Exploit DB Packet Storm
195450 5 警告 オラクル - Oracle Solaris における Apache HTTP サーバの処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3123 2012-07-20 16:06 2012-07-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 2, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
891 - - - A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6. - CVE-2024-53588 2025-01-25 07:15 2025-01-24 Show GitHub Exploit DB Packet Storm
892 6.1 MEDIUM
Network
icopydoc xml_for_google_merchant_center The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient in… CWE-79
Cross-site Scripting
CVE-2024-13406 2025-01-25 06:20 2025-01-22 Show GitHub Exploit DB Packet Storm
893 3.5 LOW
Network
- - A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The … CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0710 2025-01-25 06:15 2025-01-25 Show GitHub Exploit DB Packet Storm
894 2.4 LOW
Network
- - A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipul… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0709 2025-01-25 06:15 2025-01-25 Show GitHub Exploit DB Packet Storm
895 - - - Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does … - CVE-2025-24025 2025-01-25 06:15 2025-01-25 Show GitHub Exploit DB Packet Storm
896 - - - Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component - CVE-2024-57556 2025-01-25 06:15 2025-01-24 Show GitHub Exploit DB Packet Storm
897 6.1 MEDIUM
Network
themify themify_builder The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, … CWE-79
Cross-site Scripting
CVE-2024-13319 2025-01-25 06:06 2025-01-22 Show GitHub Exploit DB Packet Storm
898 7.2 HIGH
Network
aipower aipower The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_conten… CWE-502
 Deserialization of Untrusted Data
CVE-2025-0428 2025-01-25 05:56 2025-01-22 Show GitHub Exploit DB Packet Storm
899 4.3 MEDIUM
Network
thimpress wp_hotel_booking The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and in… CWE-862
 Missing Authorization
CVE-2024-13447 2025-01-25 05:53 2025-01-22 Show GitHub Exploit DB Packet Storm
900 7.2 HIGH
Network
aipower aipower The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_conten… CWE-502
 Deserialization of Untrusted Data
CVE-2025-0429 2025-01-25 05:51 2025-01-22 Show GitHub Exploit DB Packet Storm