Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 16, 2025, 2:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198321 5.1 警告 drake team - Drake CMS の index.php における CRLF インジェクションの脆弱性 - CVE-2007-2618 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198322 7.5 危険 crie sue - Crie seu PHPLojaFacil における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2615 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198323 6.8 警告 cgx - CGX における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2611 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198324 7.5 危険 gnuedu - gnuedu における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-2609 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198325 7.8 危険 Firebird Project - Firebird におけるバッファオーバーフローの脆弱性 - CVE-2007-2606 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198326 7.1 危険 brujula toolbar - Brujula Toolbar の BRUJULA4.NET.DLL におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2605 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198327 7.8 危険 brew city software - FlexLabel ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2604 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198328 7.8 危険 audio cd tools - Audio CD Ripper OCX ActiveX コントロールの Init 関数におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2603 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198329 9.3 危険 divx city - fix.dll の GDivX Zenith Player AviFixer クラスの ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2007-2601 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
198330 7.5 危険 agner fog - aForum の common/func.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2596 2012-06-26 15:46 2007-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 16, 2025, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
591 8.8 HIGH
Network
- - An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access. New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-11497 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
592 - - - An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addres… New CWE-346
 Origin Validation Error
CVE-2023-46715 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
593 - - - A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial… New CWE-476
 NULL Pointer Dereference
CVE-2023-42786 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
594 - - - A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial… New CWE-476
 NULL Pointer Dereference
CVE-2023-42785 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
595 - - - An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6… New CWE-78
OS Command 
CVE-2023-37937 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
596 - - - A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 al… New CWE-321
 Use of Hard-coded Cryptographic Key
CVE-2023-37936 2025-01-14 23:15 2025-01-14 Show GitHub Exploit DB Packet Storm
597 7.4 HIGH
Network
- - A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to by… New CWE-90
LDAP Injection
CVE-2024-56841 2025-01-14 20:15 2025-01-14 Show GitHub Exploit DB Packet Storm
598 4.7 MEDIUM
Network
- - A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an a… New CWE-79
Cross-site Scripting
CVE-2024-45385 2025-01-14 20:15 2025-01-14 Show GitHub Exploit DB Packet Storm
599 6.5 MEDIUM
Network
- - A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.… New CWE-552
 Files or Directories Accessible to External Parties
CVE-2024-53649 2025-01-14 20:15 2025-01-14 Show GitHub Exploit DB Packet Storm
600 6.4 MEDIUM
Network
- - The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input san… New CWE-79
Cross-site Scripting
CVE-2024-12240 2025-01-14 20:15 2025-01-14 Show GitHub Exploit DB Packet Storm