Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
261 5.4 警告
Network
creativethemes blocksy companion creativethemes の WordPress 用 blocksy companion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4487 2025-01-29 13:46 2024-05-14 Show GitHub Exploit DB Packet Storm
262 8.1 重要
Network
miniOrange Miniorange OTP Verification with Firebase miniOrange の WordPress 用 Miniorange OTP Verification with Firebase における重要な機能に対する認証の欠如に関する脆弱性 CWE-288
CWE-306
CVE-2024-9861 2025-01-29 13:46 2024-10-17 Show GitHub Exploit DB Packet Storm
263 5.5 警告
Local
デル Dell Grab デルの Windows 用 Dell Grab におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2024-25957 2025-01-29 12:07 2024-03-26 Show GitHub Exploit DB Packet Storm
264 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3989 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
265 5.4 警告
Network
creativethemes blocksy creativethemes の WordPress 用 blocksy におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4158 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
266 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21777 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
267 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21862 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
268 9.8 緊急
Network
クアルコム (複数の製品) キヤノン製スモールオフィス向け複合機およびレーザービームプリンターにおける複数の境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2024-12647
CVE-2024-12648
CVE-2024-12649
2025-01-29 11:42 2025-01-28 Show GitHub Exploit DB Packet Storm
269 5.4 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3337 2025-01-29 11:42 2024-05-2 Show GitHub Exploit DB Packet Storm
270 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-25151 2025-01-29 11:42 2024-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 14, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1311 - - - Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response… CWE-346
 Origin Validation Error
CVE-2024-55948 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1312 2.7 LOW
Network
- - IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This inform… CWE-209
Information Exposure Through an Error Message
CVE-2024-45658 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1313 5.0 MEDIUM
Local
- - IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-45657 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1314 5.9 MEDIUM
Network
- - IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized acto… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2024-43187 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1315 6.1 MEDIUM
Network
- - IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript cod… CWE-79
Cross-site Scripting
CVE-2024-40700 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1316 6.5 MEDIUM
Network
- - IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transm… CWE-352
 Origin Validation Error
CVE-2024-35138 2025-02-5 06:15 2025-02-5 Show GitHub Exploit DB Packet Storm
1317 - - - The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against … - CVE-2024-13099 2025-02-5 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1318 - - - The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be … - CVE-2024-13098 2025-02-5 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1319 - - - The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against h… - CVE-2024-13097 2025-02-5 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1320 - - - The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored … - CVE-2024-13096 2025-02-5 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm