Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 9, 2025, 6:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198941 7.5 危険 DeltaScripts - PHP Classifieds における SQL インジェクションの脆弱性 - CVE-2006-5208 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198942 10 危険 CA Technologies - 複数の CA 製品で使用される RPC インターフェースにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-5171 2012-06-26 15:37 2007-01-11 Show GitHub Exploit DB Packet Storm
198943 5 警告 アドビシステムズ - Adobe Breeze Licensed Server および Breeze Licensed Server における任意のファイルを読まれる脆弱性 - CVE-2006-5200 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198944 2.1 注意 アドビシステムズ - Adobe Contribute Publishing Server におけるサーバへのアクセス権限を取得される脆弱性 - CVE-2006-5199 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198945 7.5 危険 bulletin board ace - BBaCE の includes/functions.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5187 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198946 7.5 危険 dayfox designs - Dayfox Designs Dayfox Blog における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5183 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198947 7.5 危険 dan jensen - Dan Jensen Travelsized CMS の frontpage.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5182 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198948 7.5 危険 baumedia - Sebastian Baumann の include/main.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5180 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
198949 5.1 警告 basilix - BasiliX における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5167 2012-06-26 15:37 2006-10-5 Show GitHub Exploit DB Packet Storm
198950 7.5 危険 deluxebb - DeluxeBB の cp/sig.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5154 2012-06-26 15:37 2006-10-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 9, 2025, 4:56 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
481 - - - A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /_parse/_call_main_search_ajax.php of th… Update - CVE-2024-13093 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
482 - - - A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknown code of the file /_parse/_call_job/search_ajax.php of the component Job Post … Update - CVE-2024-13092 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
483 - - - The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in … Update - CVE-2024-12595 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
484 - - - The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scriptin… Update - CVE-2024-11357 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
485 - - - The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts Update - CVE-2024-11184 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
486 - - - Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx. Update - CVE-2024-56829 2025-01-7 06:15 2025-01-2 Show GitHub Exploit DB Packet Storm
487 - - - Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave serv… New CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2025-21617 2025-01-7 05:15 2025-01-7 Show GitHub Exploit DB Packet Storm
488 - - - Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template. New - CVE-2024-55529 2025-01-7 05:15 2025-01-7 Show GitHub Exploit DB Packet Storm
489 - - - A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the… New - CVE-2024-46073 2025-01-7 05:15 2025-01-7 Show GitHub Exploit DB Packet Storm
490 - - - File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then p… New - CVE-2024-56828 2025-01-7 03:15 2025-01-7 Show GitHub Exploit DB Packet Storm