Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 24, 2025, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199931 7.5 危険 epistemon - Epistemon の inc/common.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0701 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
199932 6.8 警告 free lan intra internet portal - FLIP におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0696 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
199933 7.5 危険 free lan intra internet portal - FLIP における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0695 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
199934 4.3 警告 diangemilang - DGNews の footer.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0694 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
199935 6.8 警告 diangemilang - DGNews の news.php における SQL インジェクションの脆弱性 - CVE-2007-0693 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
199936 5 警告 dgnews - DGNews における重要な情報を取得される脆弱性 - CVE-2007-0692 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
199937 7.5 危険 cerulean portal system - Cerulean Portal System の portal.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0684 2012-06-26 15:46 2007-02-2 Show GitHub Exploit DB Packet Storm
199938 7.5 危険 extcalendar - ExtCalendar の profile.php における任意のパスワードを変更される脆弱性 - CVE-2007-0681 2012-06-26 15:46 2007-02-2 Show GitHub Exploit DB Packet Storm
199939 7.5 危険 fullaspsite - Fullaspsite Asp Hosting Sitesi の windows.asp における SQL インジェクションの脆弱性 - CVE-2007-0678 2012-06-26 15:46 2007-02-2 Show GitHub Exploit DB Packet Storm
199940 7.5 危険 cronosys - Cadre PHP Framework の fw/class.Quick_Config_Browser.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0677 2012-06-26 15:46 2007-02-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 24, 2025, 4:45 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
871 6.5 MEDIUM
Network
- - The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions up to, and including, 0.4. This makes it possible… CWE-862
 Missing Authorization
CVE-2024-13367 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
872 6.1 MEDIUM
Network
- - The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versions up to, and including, 0.4 due to insufficient input sanitization and output … CWE-79
Cross-site Scripting
CVE-2024-13366 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
873 5.3 MEDIUM
Network
- - The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.05 via the export functionality. The JSON files are stored in predictable… CWE-200
Information Exposure
CVE-2024-12637 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
874 6.4 MEDIUM
Network
- - The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input … CWE-79
Cross-site Scripting
CVE-2024-12598 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
875 6.4 MEDIUM
Network
- - The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'glofox_lead_capture ' shortcodes in all versions up to, and including, 2.6 due t… CWE-79
Cross-site Scripting
CVE-2024-12508 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
876 6.1 MEDIUM
Network
- - The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.2.1.1 due to insufficient input sanitization an… CWE-79
Cross-site Scripting
CVE-2024-12466 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
877 4.4 MEDIUM
Network
- - The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in all versions up to, and including, 5.2 due to insufficient input sanitization a… CWE-79
Cross-site Scripting
CVE-2024-12203 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
878 - - - TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is… - CVE-2024-11146 2025-01-17 16:15 2025-01-17 Show GitHub Exploit DB Packet Storm
879 7.5 HIGH
Network
- - The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This m… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-13333 2025-01-17 15:15 2025-01-17 Show GitHub Exploit DB Packet Storm
880 6.5 MEDIUM
Network
- - The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for authentic… CWE-22
Path Traversal
CVE-2024-10799 2025-01-17 15:15 2025-01-17 Show GitHub Exploit DB Packet Storm