Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204591 6.5 警告 g.rodola - pyftpdlib の FTPServer.py におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7262 2012-03-27 18:42 2007-11-26 Show GitHub Exploit DB Packet Storm
204592 6.5 警告 g.rodola - pyftpdlib の ftp_PORT 関数における FTP バウンス攻撃を誘発する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6741 2012-03-27 18:42 2007-06-18 Show GitHub Exploit DB Packet Storm
204593 4 警告 g.rodola - pyftpdlib の ftp_STOU 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6740 2012-03-27 18:42 2007-07-18 Show GitHub Exploit DB Packet Storm
204594 5 警告 g.rodola - pyftpdlib の FTPServer.py におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6739 2012-03-27 18:42 2007-05-18 Show GitHub Exploit DB Packet Storm
204595 7.5 危険 g.rodola - pyftpdlib の FTPServer.py におけるアクセスを取得される脆弱性 CWE-287
不適切な認証
CVE-2007-6737 2012-03-27 18:42 2007-07-13 Show GitHub Exploit DB Packet Storm
204596 6.5 警告 g.rodola - pyftpdlib の FTPServer.py におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6736 2012-03-27 18:42 2007-06-15 Show GitHub Exploit DB Packet Storm
204597 4 警告 IBM - IBM FileNet P8AE の Workplace コンポーネントにおけるアクセス制限を回避する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2006-7242 2012-03-27 18:42 2010-09-20 Show GitHub Exploit DB Packet Storm
204598 4 警告 IBM - IBM FileNet P8AE の Image Viewer コンポーネントにおけるアクセス制限を回避する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2006-7241 2012-03-27 18:42 2010-09-20 Show GitHub Exploit DB Packet Storm
204599 7.2 危険 GNOME Project - gnome-power-manager における無人のラップトップにアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2006-7240 2012-03-27 18:42 2010-09-7 Show GitHub Exploit DB Packet Storm
204600 5 警告 Apache Software Foundation - Apache Wicket におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-1089 2012-03-27 14:46 2012-03-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 3, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
331 9.1 CRITICAL
Network
apple watchos
ipados
iphone_os
The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account. NVD-CWE-noinfo
CVE-2024-54512 2025-01-31 02:20 2025-01-28 Show GitHub Exploit DB Packet Storm
332 5.4 MEDIUM
Network
philantro philantro The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.3 du… CWE-79
Cross-site Scripting
CVE-2024-13527 2025-01-31 02:18 2025-01-28 Show GitHub Exploit DB Packet Storm
333 6.3 MEDIUM
Network
- - A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipul… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-0873 2025-01-31 02:15 2025-01-31 Show GitHub Exploit DB Packet Storm
334 - - - In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Ser… - CVE-2025-0367 2025-01-31 02:15 2025-01-31 Show GitHub Exploit DB Packet Storm
335 - - - A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally auth… - CVE-2024-2658 2025-01-31 02:15 2025-01-31 Show GitHub Exploit DB Packet Storm
336 - - - Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection. - CVE-2024-54851 2025-01-31 02:15 2025-01-30 Show GitHub Exploit DB Packet Storm
337 - - - HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter. - CVE-2024-51182 2025-01-31 02:15 2025-01-30 Show GitHub Exploit DB Packet Storm
338 7.8 HIGH
Local
apple macos An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to cause unexpected … CWE-787
 Out-of-bounds Write
CVE-2024-54509 2025-01-31 02:13 2025-01-28 Show GitHub Exploit DB Packet Storm
339 6.5 MEDIUM
Network
apple watchos
tvos
visionos
iphone_os
macos
ipados
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS S… NVD-CWE-noinfo
CVE-2024-54497 2025-01-31 02:11 2025-01-28 Show GitHub Exploit DB Packet Storm
340 5.3 MEDIUM
Network
apple iphone_os
macos
ipados
A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sonoma 14.7.2, macOS Sequoia 15.2. Photos in the H… NVD-CWE-noinfo
CVE-2024-54488 2025-01-31 02:04 2025-01-28 Show GitHub Exploit DB Packet Storm