Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224371 7.8 危険 マイクロソフト - 複数の Microsoft Windows 製品の TCP/IP の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-3183 2013-08-15 15:35 2013-08-13 Show GitHub Exploit DB Packet Storm
224372 7.8 危険 マイクロソフト - Microsoft Windows Server 2012 の Windows NAT ドライバサービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-3182 2013-08-15 15:31 2013-08-13 Show GitHub Exploit DB Packet Storm
224373 9.3 危険 マイクロソフト - Microsoft Windows XP および Windows Server 2003 の Unicode スクリプトプロセッサにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-3181 2013-08-15 15:27 2013-08-13 Show GitHub Exploit DB Packet Storm
224374 10 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3175 2013-08-15 15:21 2013-08-13 Show GitHub Exploit DB Packet Storm
224375 9.3 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird におけるクローム特権で任意の JavaScript コードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1697 2013-08-14 17:29 2013-06-25 Show GitHub Exploit DB Packet Storm
224376 4.3 警告 Mozilla Foundation - Mozilla Firefox および Thunderbird の SVG フィルタの実装におけるピクセル値を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1693 2013-08-14 17:26 2013-06-25 Show GitHub Exploit DB Packet Storm
224377 4.3 警告 Mozilla Foundation - Mozilla Firefox および Thunderbird におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1692 2013-08-14 17:22 2013-06-25 Show GitHub Exploit DB Packet Storm
224378 9.3 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird の SOW および COW の実装における任意の JavaScript コードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1687 2013-08-14 16:53 2013-06-25 Show GitHub Exploit DB Packet Storm
224379 10 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird の mozilla::ResetDir 関数における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2013-1686 2013-08-14 16:51 2013-06-25 Show GitHub Exploit DB Packet Storm
224380 9.3 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird の nsIDocument::GetRootElement 関数における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2013-1685 2013-08-14 16:50 2013-06-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314041 9.8 CRITICAL
Network
soplanning soplanning An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulne… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-27113 2024-09-19 03:43 2024-09-11 Show GitHub Exploit DB Packet Storm
314042 9.8 CRITICAL
Network
soplanning soplanning A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying d… CWE-89
SQL Injection
CVE-2024-27112 2024-09-19 03:42 2024-09-11 Show GitHub Exploit DB Packet Storm
314043 9.8 CRITICAL
Network
agpt autogpt A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific com… CWE-78
OS Command 
CVE-2024-6091 2024-09-19 03:41 2024-09-11 Show GitHub Exploit DB Packet Storm
314044 9.8 CRITICAL
Network
reedos aim-star This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulner… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2024-45790 2024-09-19 03:38 2024-09-11 Show GitHub Exploit DB Packet Storm
314045 7.5 HIGH
Network
pxlrbt filament_excel Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the … CWE-22
Path Traversal
CVE-2024-42485 2024-09-19 03:31 2024-08-13 Show GitHub Exploit DB Packet Storm
314046 6.5 MEDIUM
Adjacent
zyxel gs1900-48hpv2_firmware
gs1900-48_firmware
gs1900-24hpv2_firmware
gs1900-24ep_firmware
gs1900-24e_firmware
gs1900-24_firmware
gs1900-16_firmware
gs1900-10hp_firmware
gs1900-8hp…
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2… CWE-331
 Insufficient Entropy
CVE-2024-38270 2024-09-19 03:23 2024-09-10 Show GitHub Exploit DB Packet Storm
314047 6.5 MEDIUM
Network
reedos aim-star This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vul… NVD-CWE-Other
CVE-2024-45787 2024-09-19 03:15 2024-09-11 Show GitHub Exploit DB Packet Storm
314048 5.3 MEDIUM
Network
bplugins html5_video_player The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5… CWE-862
 Missing Authorization
CVE-2024-7727 2024-09-19 03:07 2024-09-11 Show GitHub Exploit DB Packet Storm
314049 9.8 CRITICAL
Network
spip spip SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipar… NVD-CWE-Other
CVE-2024-8517 2024-09-19 03:05 2024-09-7 Show GitHub Exploit DB Packet Storm
314050 4.3 MEDIUM
Network
bplugins html5_video_player The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in… CWE-862
 Missing Authorization
CVE-2024-7721 2024-09-19 03:01 2024-09-11 Show GitHub Exploit DB Packet Storm