Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 18, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201 7.5 重要
Network
Fedora Project
日本電気
ISC, Inc.
NEC Multimedia OLAP for 映像分析サービス
Fedora
ESMPRO/ServerAgent
BIND
NetApp の ONTAP (旧 Clustered Data ONTAP) 等複数ベンダの製品における脆弱性 Update CWE-noinfo
情報不足
CVE-2023-4408 2025-01-17 13:10 2023-08-18 Show GitHub Exploit DB Packet Storm
202 9.8 緊急
Network
Apache Software Foundation Apache Struts Apache Struts 2 における外部からアクセス可能なファイルの脆弱性 (S2-066) Update CWE-552
外部からアクセス可能なファイルまたはディレクトリ
CVE-2023-50164 2025-01-17 12:58 2023-12-8 Show GitHub Exploit DB Packet Storm
203 9.8 緊急
Network
Apache Software Foundation hertzbeat Apache Software Foundation の hertzbeat におけるインジェクションに関する脆弱性 New CWE-74
CWE-74
CVE-2023-51388 2025-01-17 12:08 2023-12-18 Show GitHub Exploit DB Packet Storm
204 9.8 緊急
Network
Ivanti Avalanche Ivanti の Avalanche におけるパストラバーサルの脆弱性 New CWE-22
CWE-22
CWE-288
CVE-2024-13179 2025-01-17 12:08 2025-01-14 Show GitHub Exploit DB Packet Storm
205 5.4 警告
Network
Themeisle Orbit Fox ThemeIsle の WordPress 用 Orbit Fox におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-13183 2025-01-17 12:08 2025-01-10 Show GitHub Exploit DB Packet Storm
206 4.3 警告
Network
Progress Software Corporation MOVEit Transfer Progress Software Corporation の MOVEit Transfer における脆弱性 New CWE-778
CWE-Other
CVE-2024-2291 2025-01-17 12:08 2024-03-20 Show GitHub Exploit DB Packet Storm
207 4.8 警告
Network
MantisBT Group MantisBT MantisBT Group の MantisBT におけるクロスサイトスクリプティングの脆弱性 New CWE-79
CWE-79
CVE-2024-34081 2025-01-17 12:08 2024-05-14 Show GitHub Exploit DB Packet Storm
208 8.8 重要
Network
oretnom23 Laundry Shop Management System Oretnom23 の Laundry Shop Management System における SQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2024-3466 2025-01-17 12:08 2024-04-8 Show GitHub Exploit DB Packet Storm
209 4.3 警告
Network
Brizy brizy Brizy の WordPress 用 brizy における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-3711 2025-01-17 12:02 2024-05-23 Show GitHub Exploit DB Packet Storm
210 9.8 緊急
Network
Apache Software Foundation Apache Xerces-C++ Apache Software Foundation の Apache Xerces-C++ における解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2024-23807 2025-01-17 12:02 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
421 - - - Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, bein… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-0471 2025-01-16 22:15 2025-01-16 Show GitHub Exploit DB Packet Storm
422 - - - In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a … New - CVE-2025-23013 2025-01-16 22:15 2025-01-15 Show GitHub Exploit DB Packet Storm
423 7.5 HIGH
Network
- - An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption. New CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2018-25108 2025-01-16 20:15 2025-01-16 Show GitHub Exploit DB Packet Storm
424 - - - A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 th… New CWE-1390
 Weak Authentication
CVE-2024-50563 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
425 6.4 MEDIUM
Network
- - The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shortcode in all versions up to, and including, 1.2.9 due to insufficient input san… New CWE-79
Cross-site Scripting
CVE-2024-13387 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
426 5.4 MEDIUM
Network
- - The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() functi… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-13355 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
427 6.5 MEDIUM
Network
- - The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping … New CWE-89
SQL Injection
CVE-2024-12615 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
428 7.5 HIGH
Network
- - The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versi… New CWE-89
SQL Injection
CVE-2024-12614 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
429 7.5 HIGH
Network
- - The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping… New CWE-89
SQL Injection
CVE-2024-12613 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm
430 5.3 MEDIUM
Network
- - The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.… New CWE-862
 Missing Authorization
CVE-2024-12427 2025-01-16 19:15 2025-01-16 Show GitHub Exploit DB Packet Storm