Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197441 7.5 危険 gmitc
Joomla!
- Joomla! の Green Mountain Information Technology および Consulting dbquery コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6841 2012-06-26 16:10 2009-07-1 Show GitHub Exploit DB Packet Storm
197442 6.8 警告 christof bruyland - V-webmail における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6840 2012-06-26 16:10 2009-07-1 Show GitHub Exploit DB Packet Storm
197443 10 危険 fuzzylime - fuzzylime (cms) における ディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6834 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
197444 10 危険 fuzzylime - fuzzylime (cms) の commsrss.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6833 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
197445 6.8 警告 Atlassian - Atlassian JIRA Enterprise Edition におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6832 2012-06-26 16:10 2009-06-8 Show GitHub Exploit DB Packet Storm
197446 4.3 警告 Atlassian - Atlassian JIRA Enterprise Edition におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6831 2012-06-26 16:10 2009-06-8 Show GitHub Exploit DB Packet Storm
197447 10 危険 a-link - A-LINK のWL54AP3 および WL54AP2 の管理インタフェースにおけるアクセス権を取得される脆弱性 CWE-310
暗号の問題
CVE-2008-6824 2012-06-26 16:10 2009-06-4 Show GitHub Exploit DB Packet Storm
197448 6.8 警告 a-link - A-LINK のWL54AP3 および WL54AP2 の管理インタフェースにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6823 2012-06-26 16:10 2009-06-4 Show GitHub Exploit DB Packet Storm
197449 10 危険 Eaton - Eaton MGEOPS Network Shutdown Module における任意のコードを実行される脆弱性 CWE-287
不適切な認証
CVE-2008-6816 2012-06-26 16:10 2009-05-28 Show GitHub Exploit DB Packet Storm
197450 4 警告 シトリックス・システムズ - Citrix Web Interface for Java Application Servers のセッション切断機能におけるユーザの Web インターフェースセッションへのアクセス権を取得される脆弱性 CWE-Other
その他
CVE-2008-6830 2012-06-26 16:10 2008-10-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1441 - - - DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when running the impacted … - CVE-2024-9494 2025-01-25 00:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1442 - - - DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  ToolStick installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. - CVE-2024-9493 2025-01-25 00:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1443 - - - DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted ins… - CVE-2024-9492 2025-01-25 00:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1444 - - - DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running the impacted instal… - CVE-2024-9491 2025-01-25 00:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1445 - - - DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to privilege escalation and arbitrary code execution when running the impacted inst… - CVE-2024-9490 2025-01-25 00:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1446 - - - An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS… - CVE-2024-57184 2025-01-25 00:15 2025-01-24 Show GitHub Exploit DB Packet Storm
1447 - - - GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns - CVE-2022-47090 2025-01-25 00:15 2025-01-24 Show GitHub Exploit DB Packet Storm
1448 - - - Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenticated users with Admin Console access to retrieve sensitive data, including app… - CVE-2021-42718 2025-01-25 00:15 2025-01-24 Show GitHub Exploit DB Packet Storm
1449 8.8 HIGH
Network
- - IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion. CWE-427
 Uncontrolled Search Path Element
CVE-2024-41739 2025-01-24 23:15 2025-01-24 Show GitHub Exploit DB Packet Storm
1450 5.4 MEDIUM
Network
- - The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. Thi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-11913 2025-01-24 23:15 2025-01-24 Show GitHub Exploit DB Packet Storm