Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
261 5.4 警告
Network
creativethemes blocksy companion creativethemes の WordPress 用 blocksy companion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4487 2025-01-29 13:46 2024-05-14 Show GitHub Exploit DB Packet Storm
262 8.1 重要
Network
miniOrange Miniorange OTP Verification with Firebase miniOrange の WordPress 用 Miniorange OTP Verification with Firebase における重要な機能に対する認証の欠如に関する脆弱性 CWE-288
CWE-306
CVE-2024-9861 2025-01-29 13:46 2024-10-17 Show GitHub Exploit DB Packet Storm
263 5.5 警告
Local
デル Dell Grab デルの Windows 用 Dell Grab におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2024-25957 2025-01-29 12:07 2024-03-26 Show GitHub Exploit DB Packet Storm
264 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3989 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
265 5.4 警告
Network
creativethemes blocksy creativethemes の WordPress 用 blocksy におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4158 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
266 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21777 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
267 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21862 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
268 9.8 緊急
Network
クアルコム (複数の製品) キヤノン製スモールオフィス向け複合機およびレーザービームプリンターにおける複数の境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2024-12647
CVE-2024-12648
CVE-2024-12649
2025-01-29 11:42 2025-01-28 Show GitHub Exploit DB Packet Storm
269 5.4 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3337 2025-01-29 11:42 2024-05-2 Show GitHub Exploit DB Packet Storm
270 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-25151 2025-01-29 11:42 2024-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 11, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1151 - - - snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporar… CWE-276
Incorrect Default Permissions 
CVE-2025-24788 2025-01-30 06:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1152 7.3 HIGH
Network
- - A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to … CWE-20
CWE-502
 Improper Input Validation 
 Deserialization of Untrusted Data
CVE-2025-0841 2025-01-30 06:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1153 - - - 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is requi… - CVE-2025-0411 2025-01-30 06:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1154 - - - mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affe… CWE-78
OS Command 
CVE-2025-20061 2025-01-30 05:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1155 - - - mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the af… CWE-78
OS Command 
CVE-2025-20014 2025-01-30 05:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1156 5.0 MEDIUM
Network
- - A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argumen… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2025-0840 2025-01-30 05:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1157 - - - Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-48852 2025-01-30 04:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1158 - - - Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4. CWE-1385
 Missing Origin Validation in WebSockets
CVE-2024-48849 2025-01-30 04:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1159 - - - A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling fun… - CVE-2024-10001 2025-01-30 04:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1160 - - - regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1. CWE-20
CWE-345
 Improper Input Validation 
 Insufficient Verification of Data Authenticity
CVE-2025-24882 2025-01-30 03:15 2025-01-30 Show GitHub Exploit DB Packet Storm