Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198181 4.3 警告 civic-cms - Civic Website Manager の カレンダコントローラにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3849 2012-06-26 16:02 2008-08-27 Show GitHub Exploit DB Packet Storm
198182 4.3 警告 aguestbook - ANG におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3847 2012-06-26 16:02 2008-08-27 Show GitHub Exploit DB Packet Storm
198183 7.5 危険 craftysyntax - CSLH における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3845 2012-06-26 16:02 2008-08-27 Show GitHub Exploit DB Packet Storm
198184 5 警告 craftysyntax - Crafty Syntax Live Help (CSLH) における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-3840 2012-06-26 16:02 2008-08-27 Show GitHub Exploit DB Packet Storm
198185 7.2 危険 Condor Project - Condor におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3830 2012-06-26 16:02 2008-10-8 Show GitHub Exploit DB Packet Storm
198186 5 警告 Condor Project - Condor の condor_ schedd デーモンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-3829 2012-06-26 16:02 2008-10-8 Show GitHub Exploit DB Packet Storm
198187 4.6 警告 Condor Project - Condor の condor_ schedd デーモンにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3828 2012-06-26 16:02 2008-10-8 Show GitHub Exploit DB Packet Storm
198188 4.6 警告 Condor Project - Condor における他のユーザとしてジョブを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3826 2012-06-26 16:02 2008-10-8 Show GitHub Exploit DB Packet Storm
198189 7.5 危険 BTITeam - BtiTracker の scrape.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3784 2012-06-26 16:02 2008-08-26 Show GitHub Exploit DB Packet Storm
198190 3.5 注意 discountedscripts - ACG-PTP の admin/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3782 2012-06-26 16:02 2008-08-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 22, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1461 3.5 LOW
Network
- - A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The m… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-1169 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1462 - - - A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php.… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1168 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1463 - - - A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1167 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1464 - - - A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The mani… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-1166 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1465 - - - SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any… CWE-22
Path Traversal
CVE-2025-25243 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1466 - - - Due to a missing authorization check, an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads to … CWE-862
 Missing Authorization
CVE-2025-25241 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1467 - - - The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting ma… CWE-601
Open Redirect
CVE-2025-24876 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1468 - - - SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this … CWE-352
 Origin Validation Error
CVE-2025-24875 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1469 - - - SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers mig… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2025-24874 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1470 - - - The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build… CWE-863
 Incorrect Authorization
CVE-2025-24872 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm