Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 20, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197751 5 警告 マイクロソフト
AfterLogic
- ASP.NET 用の AfterLogic MailBee WebMail Pro の download_view_attachment.aspx におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0333 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197752 5 警告 aria - aria の arias/help/effect.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0332 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197753 7.8 危険 funkwerk - Funkwerk System Software におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-0331 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197754 7.5 危険 fascript - FaScript FaName の page.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0328 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197755 7.5 危険 fascript - FaScript FaMp3 の show.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0327 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197756 7.5 危険 fascript - FaScript FaPersianHack の class/show.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0326 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197757 7.5 危険 fascript - FaScript FaPersian Petition の show.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0325 2012-06-26 15:54 2008-01-17 Show GitHub Exploit DB Packet Storm
197758 9.3 危険 Borland Software Corporation - Borland CaliberRM 2006 の PGMWebHandler::parse_request 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0311 2012-06-26 15:54 2008-04-6 Show GitHub Exploit DB Packet Storm
197759 7.2 危険 Debian - apt-listchanges の apt-listchanges.py における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-0302 2012-06-26 15:54 2008-01-16 Show GitHub Exploit DB Packet Storm
197760 4.3 警告 アップル - Apple Safari で使用される KHTML WebKit におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-0298 2012-06-26 15:54 2008-01-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 20, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
631 - - - SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. - CVE-2025-22976 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
632 - - - SQL Injection vulnerability in DDSN Net Pty Ltd (DDSN Interactive) DDSN Interactive cm3 Acora CMS 10.1.1 allows an attacker to execute arbitrary code via the table parameter. - CVE-2025-22964 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
633 6.1 MEDIUM
Network
- - The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and includin… CWE-79
Cross-site Scripting
CVE-2025-0215 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
634 - - - An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or H… - CVE-2024-41454 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
635 - - - Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command. - CVE-2024-39967 2025-01-16 08:15 2025-01-16 Show GitHub Exploit DB Packet Storm
636 - - - An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclo… - CVE-2025-0107 2025-01-16 08:15 2025-01-11 Show GitHub Exploit DB Packet Storm
637 - - - A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer derefer… CWE-476
CWE-404
 NULL Pointer Dereference
 Improper Resource Shutdown or Release
CVE-2025-0492 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
638 - - - A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of the argument id l… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0491 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
639 - - - An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. - CVE-2024-36751 2025-01-16 07:15 2025-01-16 Show GitHub Exploit DB Packet Storm
640 - - - A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /fladmin/cat_edit.php. The manipulation of t… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0487 2025-01-16 06:15 2025-01-16 Show GitHub Exploit DB Packet Storm