Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 29, 2025, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196171 7.5 危険 WordPress.org
grupenet
- WordPress 用 WP-Lytebox プラグインの main.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4672 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196172 7.5 危険 beaussier - RoomPHPlanning の Login.php における管理アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2009-4671 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196173 7.5 危険 beaussier - RoomPHPlanning の admin/delitem.php における任意のルームを削除される脆弱性 CWE-287
不適切な認証
CVE-2009-4670 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196174 7.5 危険 beaussier - RoomPHPlanning における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4669 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196175 9.3 危険 JetAudio - jetAudio の JetCast.exe におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4668 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196176 5 警告 CuteSoft Components - ASP.NET 用の CuteSoft Components Cute Editor におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4665 2012-06-26 16:19 2010-03-5 Show GitHub Exploit DB Packet Storm
196177 3.3 注意 Linux
fwbuilder
- Firewall Builder における権限を取得される脆弱性 CWE-59
リンク解釈の問題
CVE-2009-4664 2012-06-26 16:19 2010-03-3 Show GitHub Exploit DB Packet Storm
196178 4.3 警告 BigAntSoft - BigAnt Server におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4661 2012-06-26 16:19 2010-03-3 Show GitHub Exploit DB Packet Storm
196179 10 危険 BigAntSoft - BigAnt IM Server の AntServer モジュール (AntServer.exe) におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4660 2012-06-26 16:19 2010-03-3 Show GitHub Exploit DB Packet Storm
196180 9.3 危険 e-soft.co - E-Soft DJ Studio Pro におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4656 2012-06-26 16:19 2010-03-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 29, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
511 - - - Missing Authorization vulnerability in Revmakx WP Duplicate – WordPress Migration Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Duplicate – Wor… CWE-862
 Missing Authorization
CVE-2025-24652 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
512 - - - Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-24650 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
513 - - - Missing Authorization vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhanceme… CWE-862
 Missing Authorization
CVE-2025-24649 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
514 - - - Cross-Site Request Forgery (CSRF) vulnerability in datafeedr.com WooCommerce Cloak Affiliate Links allows Cross Site Request Forgery. This issue affects WooCommerce Cloak Affiliate Links: from n/a th… CWE-352
 Origin Validation Error
CVE-2025-24647 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
515 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stor… CWE-79
Cross-site Scripting
CVE-2025-24644 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
516 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pete Dring Create with Code allows DOM-Based XSS. This issue affects Create with Code: from n/a t… CWE-79
Cross-site Scripting
CVE-2025-24638 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
517 - - - Cross-Site Request Forgery (CSRF) vulnerability in Laymance Technologies LLC MachForm Shortcode allows Stored XSS. This issue affects MachForm Shortcode: from n/a through 1.4.1. CWE-352
 Origin Validation Error
CVE-2025-24636 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
518 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Orbisius Simple Notice allows Stored XSS. This issue affects Orbisius S… CWE-79
Cross-site Scripting
CVE-2025-24634 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
519 - - - Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Build Private S… CWE-862
 Missing Authorization
CVE-2025-24633 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
520 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford, LinSoftware Blur Text allows Stored XSS. This issue affects Blur Text: from n/a t… CWE-79
Cross-site Scripting
CVE-2025-24627 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm