Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195901 5 警告 ETERNA - bozotic HTTP サーバにおけるユーザアカウントの存在を決定される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2320 2012-06-26 16:19 2010-08-2 Show GitHub Exploit DB Packet Storm
195902 6.8 警告 Nucleus
edmondhui.homeip
- Nucleus の NP_Twitter プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-2314 2012-06-26 16:19 2010-06-17 Show GitHub Exploit DB Packet Storm
195903 6.8 警告 anodyne-productions - Anodyne Productions SIMM Management System (SMS) の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-2313 2012-06-26 16:19 2010-06-17 Show GitHub Exploit DB Packet Storm
195904 7.5 危険 evological - EvoLogical EvoCam の Web サーバにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-2309 2012-06-26 16:19 2010-06-16 Show GitHub Exploit DB Packet Storm
195905 6.8 警告 D-Link Systems, Inc. - Dlink Di-604 ルータの Ping ツール Web インターフェースにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-2293 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
195906 4.3 警告 D-Link Systems, Inc. - Dlink Di-604 ルータの Ping ツール Web インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2292 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
195907 10 危険 The Dojo Foundation - Dojo の ビルド処理のディフォルト設定における詳細不明な脆弱性 CWE-16
環境設定
CVE-2010-2276 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
195908 4.3 警告 The Dojo Foundation - Dojo Toolkit SDK の dijit/tests/_testCommon.js におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2275 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
195909 4.3 警告 The Dojo Foundation - Dojo におけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2010-2274 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
195910 4.3 警告 The Dojo Foundation - Dojo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2273 2012-06-26 16:19 2010-06-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 25, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1781 - - - An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file. - CVE-2024-57408 2025-02-11 09:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1782 - - - Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vul… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2025-25194 2025-02-11 08:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1783 6.3 MEDIUM
Network
- - A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the a… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1158 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1784 - - - A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to… - CVE-2024-57177 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1785 - - - A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, in… - CVE-2024-46437 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1786 - - - Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service. - CVE-2024-46436 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1787 - - - A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. Thi… - CVE-2024-46435 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1788 - - - Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP … - CVE-2024-46434 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1789 - - - A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative pr… - CVE-2024-46433 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1790 - - - Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized ch… - CVE-2024-46432 2025-02-11 07:15 2025-02-11 Show GitHub Exploit DB Packet Storm