Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 17, 2025, 2:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-3008 2025-01-16 12:30 2024-03-27 Show GitHub Exploit DB Packet Storm
252 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-3010 2025-01-16 12:30 2024-03-28 Show GitHub Exploit DB Packet Storm
253 5.4 警告
Network
Pixelite events manager Pixelite の WordPress 用 events manager におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3492 2025-01-16 12:30 2024-06-12 Show GitHub Exploit DB Packet Storm
254 5.4 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4003 2025-01-16 12:30 2024-05-2 Show GitHub Exploit DB Packet Storm
255 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-4124 2025-01-16 12:30 2024-04-24 Show GitHub Exploit DB Packet Storm
256 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2024-4588 2025-01-16 12:30 2024-05-7 Show GitHub Exploit DB Packet Storm
257 6.1 警告
Network
Metagauss Inc. eventprime Metagauss Inc. の WordPress 用 eventprime におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-9864 2025-01-16 12:29 2024-10-24 Show GitHub Exploit DB Packet Storm
258 7.8 重要
Local
クアルコム QCA6595 ファームウェア
qam8650p ファームウェア
fastconnect 6700 ファームウェア
QCA6574A ファームウェア
qam8775p ファームウェア
flight rb5 5g ファームウェア
qam8255p ファームウェア<…
複数のクアルコム製品における解放済みメモリの使用に関する脆弱性 New CWE-416
CWE-416
CVE-2024-23354 2025-01-16 12:29 2024-05-6 Show GitHub Exploit DB Packet Storm
259 7.8 重要
Local
マイクロソフト Microsoft Excel
Microsoft 365 Apps
Microsoft Office Online Server
Microsoft Office
Microsoft Excel のリモートでコードが実行される脆弱性 New CWE-502
CWE-noinfo
CVE-2024-30042 2025-01-16 12:27 2024-05-14 Show GitHub Exploit DB Packet Storm
260 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server 2025
Microsoft Window…
Microsoft Message Queuing (MSMQ) のサービス拒否の脆弱性 New CWE-400
CWE-noinfo
CVE-2024-49096 2025-01-16 12:20 2024-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 17, 2025, 5:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
371 - - - Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the imag… New - CVE-2024-48855 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
372 - - - Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image … New - CVE-2024-48854 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
373 - - - Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials vi… New CWE-116
CWE-147
CWE-150
 Improper Encoding or Escaping of Output
 Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2024-50349 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
374 - - - Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is text-based over standard input/output, and consists… New CWE-200
Information Exposure
CVE-2024-50338 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
375 - - - Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to a… New CWE-94
CWE-502
Code Injection
 Deserialization of Untrusted Data
CVE-2024-49375 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
376 - - - .NET Elevation of Privilege Vulnerability New CWE-379
 Creation of Temporary File in Directory with Incorrect Permissions
CVE-2025-21173 2025-01-15 04:15 2025-01-15 Show GitHub Exploit DB Packet Storm
377 6.5 MEDIUM
Network
- - A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is ser… New CWE-79
Cross-site Scripting
CVE-2025-23366 2025-01-15 03:16 2025-01-15 Show GitHub Exploit DB Packet Storm
378 - - - Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary… New - CVE-2025-23052 2025-01-15 03:16 2025-01-15 Show GitHub Exploit DB Packet Storm
379 - - - An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to… New - CVE-2025-23051 2025-01-15 03:16 2025-01-15 Show GitHub Exploit DB Packet Storm
380 - - - XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**… New CWE-862
 Missing Authorization
CVE-2025-23025 2025-01-15 03:16 2025-01-15 Show GitHub Exploit DB Packet Storm