Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 24, 2025, 6:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196181 7.5 危険 Achievo - Achievo の get_employee 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2734 2012-06-26 16:10 2009-10-11 Show GitHub Exploit DB Packet Storm
196182 4.3 警告 Achievo - Achievo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2733 2012-06-26 16:10 2009-10-11 Show GitHub Exploit DB Packet Storm
196183 7.8 危険 Digium - 複数の Asterisk 製品における SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2726 2012-06-26 16:10 2009-08-12 Show GitHub Exploit DB Packet Storm
196184 5 警告 Django Software Foundation - Django の core/servers/basehttp.py の Admin メディアハンドラにおける任意のファイルを読まれる脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2659 2012-06-26 16:10 2009-08-4 Show GitHub Exploit DB Packet Storm
196185 5 警告 Digium - Asterisk Open Source の main/rtp.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2651 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
196186 4.7 警告 FreeBSD - FreeBSD の IATA (ata) ドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2649 2012-06-26 16:10 2009-07-30 Show GitHub Exploit DB Packet Storm
196187 5 警告 flashden - FlashDen Guestbook における設定情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2648 2012-06-26 16:10 2009-07-30 Show GitHub Exploit DB Packet Storm
196188 10 危険 DELL EMC (旧 EMC Corporation) - ISM Portmapper サービスの librpc.dll の認証機能における整数符号化エラーの脆弱性 CWE-189
数値処理の問題
CVE-2009-2754 2012-06-26 16:10 2010-03-5 Show GitHub Exploit DB Packet Storm
196189 9.3 危険 ditcms - dit.cms におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2784 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
196190 6 警告 Arab Portal - Arab Portal の forum.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2781 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 25, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
951 7.8 HIGH
Local
microsoft 365_apps
office
Microsoft Excel Security Feature Bypass Vulnerability NVD-CWE-noinfo
CVE-2025-21364 2025-01-18 00:11 2025-01-15 Show GitHub Exploit DB Packet Storm
952 7.8 HIGH
Local
microsoft 365_apps
office
Microsoft Word Remote Code Execution Vulnerability NVD-CWE-noinfo
CVE-2025-21363 2025-01-18 00:10 2025-01-15 Show GitHub Exploit DB Packet Storm
953 7.3 HIGH
Network
- - A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /signupconfirm.php. The manip… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0527 2025-01-17 23:15 2025-01-17 Show GitHub Exploit DB Packet Storm
954 - - - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary mo… - CVE-2024-13503 2025-01-17 23:15 2025-01-17 Show GitHub Exploit DB Packet Storm
955 - - - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion… - CVE-2024-13502 2025-01-17 23:15 2025-01-17 Show GitHub Exploit DB Packet Storm
956 - - - In the Linux kernel, the following vulnerability has been resolved: workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker After commit 746ae46c1113 ("drm/sched: Mar… - CVE-2024-57888 2025-01-17 23:15 2025-01-15 Show GitHub Exploit DB Packet Storm
957 - - - In the Linux kernel, the following vulnerability has been resolved: mm: hugetlb: independent PMD page table shared count The folio refcount may be increased unexpectly through try_get_folio() by ca… - CVE-2024-57883 2025-01-17 23:15 2025-01-15 Show GitHub Exploit DB Packet Storm
958 - - - In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH… - CVE-2024-53685 2025-01-17 23:15 2025-01-11 Show GitHub Exploit DB Packet Storm
959 - - - CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when a non-admin authenticated… CWE-502
 Deserialization of Untrusted Data
CVE-2024-12703 2025-01-17 20:15 2025-01-17 Show GitHub Exploit DB Packet Storm
960 - - - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web page, modification of web page and denial of service… CWE-200
Information Exposure
CVE-2024-12142 2025-01-17 20:15 2025-01-17 Show GitHub Exploit DB Packet Storm