Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197081 7.5 危険 boxalino - Boxalino の client/desktop/default.htm におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1479 2012-06-26 16:10 2009-10-22 Show GitHub Exploit DB Packet Storm
197082 10 危険 aten - ATEN KH1516i IP KVM スイッチ上の https Web インターフェースにおける https セッションを解読される脆弱性 CWE-310
暗号の問題
CVE-2009-1477 2012-06-26 16:10 2009-05-27 Show GitHub Exploit DB Packet Storm
197083 7.2 危険 darren reed - Darren Reed IPFilter の lib/load_http.c におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1476 2012-06-26 16:10 2009-05-26 Show GitHub Exploit DB Packet Storm
197084 7.6 危険 aten - ATEN KH1516i IP KVM スイッチにおけるクッキーを取得される脆弱性 CWE-310
暗号の問題
CVE-2009-1474 2012-06-26 16:10 2009-05-27 Show GitHub Exploit DB Packet Storm
197085 10 危険 aten - ATEN KH1516i IP KVM スイッチの Windows クライアントプログラムにおける中間者攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2009-1473 2012-06-26 16:10 2009-05-27 Show GitHub Exploit DB Packet Storm
197086 10 危険 aten - ATEN KH1516i IP KVM スイッチの Java クライアントプログラムにおけるスイッチへ接続されているマシンへのアクセス権を取得される脆弱性 CWE-310
暗号の問題
CVE-2009-1472 2012-06-26 16:10 2009-05-27 Show GitHub Exploit DB Packet Storm
197087 4.3 警告 evolution-extreme - Nuke Evolution Xtreme の player.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1457 2012-06-26 16:10 2009-04-28 Show GitHub Exploit DB Packet Storm
197088 6.8 警告 Andrew Simpson - WebCollab におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-1455 2012-06-26 16:10 2009-04-28 Show GitHub Exploit DB Packet Storm
197089 4.3 警告 Andrew Simpson - WebCollab の tasks.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1454 2012-06-26 16:10 2009-04-28 Show GitHub Exploit DB Packet Storm
197090 6.8 警告 anoochit chalothorn - Tiny Blogr の class.eport.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1453 2012-06-26 16:10 2009-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 12, 2025, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1681 - - - vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim o… CWE-284
Improper Access Control
CVE-2025-24365 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1682 - - - vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code … CWE-74
Injection
CVE-2025-24364 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1683 - - - vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses t… CWE-502
 Deserialization of Untrusted Data
CVE-2025-24357 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1684 - - - fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peer… CWE-405
 Asymmetric Resource Consumption (Amplification)
CVE-2025-24356 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1685 - - - imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose servi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2025-24354 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1686 - - - matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured wi… CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2025-23197 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1687 4.5 MEDIUM
Local
- - A vulnerability, which was classified as problematic, was found in Postman up to 11.20 on Windows. This affects an unknown part in the library profapi.dll. The manipulation leads to untrusted search … CWE-426
 Untrusted Search Path
CVE-2025-0733 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1688 4.5 MEDIUM
Local
- - A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipul… CWE-426
 Untrusted Search Path
CVE-2025-0732 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1689 - - - Vision related software from NI used a third-party library for image processing that exposes several vulnerabilities. These vulnerabilities may result in arbitrary code execution. Successful exploi… - CVE-2024-12740 2025-01-28 03:15 2025-01-28 Show GitHub Exploit DB Packet Storm
1690 - - - Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss… CWE-78
OS Command 
CVE-2025-22604 2025-01-28 02:15 2025-01-28 Show GitHub Exploit DB Packet Storm