Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 23, 2024, 6:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197911 7.5 危険 Google - Linux 上で動作する Google Chrome における詳細不明な脆弱性 CWE-20
不適切な入力確認
CVE-2011-1439 2011-11-18 10:01 2011-04-27 Show GitHub Exploit DB Packet Storm
197912 7.5 危険 Google - Google Chrome における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-1438 2011-11-18 10:00 2011-04-27 Show GitHub Exploit DB Packet Storm
197913 7.5 危険 Google - Google Chrome における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2011-1437 2011-11-18 09:57 2011-04-27 Show GitHub Exploit DB Packet Storm
197914 5 警告 Google - Linux 上で動作する Google Chrome におけるサービス運用妨害 (アプリケーションクラッシュ) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-1436 2011-11-18 09:56 2011-04-27 Show GitHub Exploit DB Packet Storm
197915 5 警告 Google - Google Chrome におけるローカルファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2011-1435 2011-11-18 09:56 2011-04-27 Show GitHub Exploit DB Packet Storm
197916 5 警告 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-1434 2011-11-18 09:55 2011-04-27 Show GitHub Exploit DB Packet Storm
197917 4.3 警告 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-362
競合状態
CVE-2011-1305 2011-11-18 09:54 2011-04-27 Show GitHub Exploit DB Packet Storm
197918 5 警告 Google - Google Chrome におけるポップアップブロッカーを回避される脆弱性 CWE-noinfo
情報不足
CVE-2011-1304 2011-11-18 09:54 2011-04-27 Show GitHub Exploit DB Packet Storm
197919 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-1303 2011-11-18 09:53 2011-04-27 Show GitHub Exploit DB Packet Storm
197920 4.3 警告 サイバートラスト株式会社
Trolltech
ターボリナックス
レッドハット
- Qt の UTF-8 デコーダーにおけるクロスサイトスクリプティングおよびディレクトリトラバーサルの脆弱性 - CVE-2007-0242 2011-11-17 11:10 2007-04-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Oct. 23, 2024, 4:18 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
131 6.5 MEDIUM
Network
marvinlabs wp_customer_area The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address. Update NVD-CWE-noinfo
CVE-2023-6824 2024-10-23 01:35 2024-01-17 Show GitHub Exploit DB Packet Storm
132 8.8 HIGH
Adjacent
tianocore edk2 EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized acces… Update CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2023-45230 2024-10-23 01:35 2024-01-17 Show GitHub Exploit DB Packet Storm
133 6.7 MEDIUM
Local
linuxfoundation
google
yocto
android
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee… Update CWE-787
 Out-of-bounds Write
CVE-2023-20805 2024-10-23 01:35 2023-08-7 Show GitHub Exploit DB Packet Storm
134 6.7 MEDIUM
Local
linuxfoundation
google
yocto
android
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee… Update CWE-787
 Out-of-bounds Write
CVE-2023-20804 2024-10-23 01:35 2023-08-7 Show GitHub Exploit DB Packet Storm
135 6.5 MEDIUM
Local
linuxfoundation
google
yocto
android
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed… Update CWE-787
 Out-of-bounds Write
CVE-2023-20803 2024-10-23 01:35 2023-08-7 Show GitHub Exploit DB Packet Storm
136 8.8 HIGH
Network
mozilla
debian
firefox
debian_linux
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, a… Update NVD-CWE-noinfo
CVE-2023-4047 2024-10-23 01:35 2023-08-2 Show GitHub Exploit DB Packet Storm
137 5.3 MEDIUM
Network
mozilla
debian
firefox
debian_linux
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process… Update NVD-CWE-noinfo
CVE-2023-4046 2024-10-23 01:35 2023-08-2 Show GitHub Exploit DB Packet Storm
138 5.3 MEDIUM
Network
apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5… Update CWE-89
SQL Injection
CVE-2023-30465 2024-10-23 01:35 2023-04-12 Show GitHub Exploit DB Packet Storm
139 9.8 CRITICAL
Network
apache linkis In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserializ… Update CWE-502
 Deserialization of Untrusted Data
CVE-2023-29216 2024-10-23 01:35 2023-04-10 Show GitHub Exploit DB Packet Storm
140 9.8 CRITICAL
Network
apache linkis In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulne… Update CWE-502
 Deserialization of Untrusted Data
CVE-2023-29215 2024-10-23 01:35 2023-04-10 Show GitHub Exploit DB Packet Storm