Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 29, 2025, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211 7.8 重要
Local
code-projects Scholars Tracking System fabianros の Scholars Tracking System における SQL インジェクションの脆弱性 New CWE-89
CWE-89
CVE-2024-24098 2025-01-28 10:43 2024-03-5 Show GitHub Exploit DB Packet Storm
212 5.4 警告
Network
IBM IBM UrbanCode Deploy
IBM DevOps Deploy
IBM の IBM DevOps Deploy および IBM UrbanCode Deploy におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-28781 2025-01-28 10:25 2024-05-9 Show GitHub Exploit DB Packet Storm
213 7.8 重要
Local
IBM Security Verify Access Docker IBM の Security Verify Access Docker における脆弱性 New CWE-250
CWE-Other
CVE-2024-35142 2025-01-28 10:25 2024-05-30 Show GitHub Exploit DB Packet Storm
214 7.8 重要
Local
IBM Security Verify Access Docker IBM の Security Verify Access Docker における証明書検証に関する脆弱性 New CWE-295
不正な証明書検証
CVE-2024-35140 2025-01-28 10:24 2024-05-30 Show GitHub Exploit DB Packet Storm
215 7.8 重要
Local
クアルコム sa8255p ファームウェア
snapdragon auto 5g modem-rf gen 2 ファームウェア
qcn6274 ファームウェア
Snapdragon W5+ Gen 1 Wearable Platform ファームウェア…
複数のクアルコム製品における解放済みメモリの使用に関する脆弱性 New CWE-416
CWE-416
CVE-2023-43544 2025-01-28 10:24 2023-09-19 Show GitHub Exploit DB Packet Storm
216 4.8 警告
Network
WPExperts password protected WPExperts の WordPress 用 password protected におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-0656 2025-01-28 10:24 2024-02-29 Show GitHub Exploit DB Packet Storm
217 5.4 警告
Network
moveaddons move addons for elementor moveaddons の WordPress 用 move addons for elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2131 2025-01-28 10:24 2024-03-23 Show GitHub Exploit DB Packet Storm
218 7.5 重要
Network
Magma Magma Linux Foundation の Magma における境界外読み取りに関する脆弱性 New CWE-120
CWE-125
CVE-2024-24417 2025-01-28 10:24 2024-01-25 Show GitHub Exploit DB Packet Storm
219 5.3 警告
Network
JetBrains TeamCity JetBrains の TeamCity におけるエラーメッセージによる情報漏えいに関する脆弱性 New CWE-209
CWE-209
CVE-2024-36375 2025-01-28 10:24 2024-05-29 Show GitHub Exploit DB Packet Storm
220 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. w30e ファームウェア Shenzhen Tenda Technology Co.,Ltd. の w30e ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-3879 2025-01-28 10:24 2024-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 29, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
871 7.8 HIGH
Local
- - Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low p… - CVE-2025-21532 2025-01-23 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
872 4.3 MEDIUM
Network
- - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerab… - CVE-2025-21530 2025-01-23 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
873 4.9 MEDIUM
Network
- - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Ea… - CVE-2025-21529 2025-01-23 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
874 - - - Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2025-23028 2025-01-23 02:15 2025-01-23 Show GitHub Exploit DB Packet Storm
875 7.5 HIGH
Network
- - A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (… CWE-789
CWE-476
 Memory Allocation with Excessive Size Value
 NULL Pointer Dereference
CVE-2025-20165 2025-01-23 02:15 2025-01-23 Show GitHub Exploit DB Packet Storm
876 9.9 CRITICAL
Network
- - A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vuln… CWE-274
CWE-276
 Improper Handling of Insufficient Privileges
Incorrect Default Permissions 
CVE-2025-20156 2025-01-23 02:15 2025-01-23 Show GitHub Exploit DB Packet Storm
877 5.3 MEDIUM
Network
- - A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected d… CWE-122
CWE-120
Heap-based Buffer Overflow
Classic Buffer Overflow
CVE-2025-20128 2025-01-23 02:15 2025-01-23 Show GitHub Exploit DB Packet Storm
878 4.4 MEDIUM
Network
- - IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr… CWE-79
Cross-site Scripting
CVE-2024-51457 2025-01-23 02:15 2025-01-23 Show GitHub Exploit DB Packet Storm
879 - - - In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. Th… - CVE-2024-49734 2025-01-23 02:15 2025-01-22 Show GitHub Exploit DB Packet Storm
880 4.3 MEDIUM
Network
07fly 07flycms 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html CWE-352
 Origin Validation Error
CVE-2024-57161 2025-01-23 02:15 2025-01-17 Show GitHub Exploit DB Packet Storm