Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
261 5.4 警告
Network
creativethemes blocksy companion creativethemes の WordPress 用 blocksy companion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4487 2025-01-29 13:46 2024-05-14 Show GitHub Exploit DB Packet Storm
262 8.1 重要
Network
miniOrange Miniorange OTP Verification with Firebase miniOrange の WordPress 用 Miniorange OTP Verification with Firebase における重要な機能に対する認証の欠如に関する脆弱性 CWE-288
CWE-306
CVE-2024-9861 2025-01-29 13:46 2024-10-17 Show GitHub Exploit DB Packet Storm
263 5.5 警告
Local
デル Dell Grab デルの Windows 用 Dell Grab におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2024-25957 2025-01-29 12:07 2024-03-26 Show GitHub Exploit DB Packet Storm
264 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3989 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
265 5.4 警告
Network
creativethemes blocksy creativethemes の WordPress 用 blocksy におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4158 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
266 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21777 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
267 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21862 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
268 9.8 緊急
Network
クアルコム (複数の製品) キヤノン製スモールオフィス向け複合機およびレーザービームプリンターにおける複数の境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2024-12647
CVE-2024-12648
CVE-2024-12649
2025-01-29 11:42 2025-01-28 Show GitHub Exploit DB Packet Storm
269 5.4 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3337 2025-01-29 11:42 2024-05-2 Show GitHub Exploit DB Packet Storm
270 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-25151 2025-01-29 11:42 2024-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274341 - verliadmin verliadmin Cross-site scripting (XSS) vulnerability in VerliAdmin 0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this informatio… NVD-CWE-Other
CVE-2006-6668 2011-03-8 11:46 2006-12-21 Show GitHub Exploit DB Packet Storm
274342 - nortel callpilot_server Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL. NVD-CWE-Other
CVE-2006-6670 2011-03-8 11:46 2006-12-21 Show GitHub Exploit DB Packet Storm
274343 - maxiasp burak_yilmaz_download_portal Multiple SQL injection vulnerabilities in Burak Yylmaz Download Portal allow remote attackers to execute arbitrary SQL commands via the (1) kid or possibly (2) id parameter to (a) HABERLER.ASP and (b… NVD-CWE-Other
CVE-2006-6672 2011-03-8 11:46 2006-12-21 Show GitHub Exploit DB Packet Storm
274344 - netrik netrik The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands … NVD-CWE-Other
CVE-2006-6678 2011-03-8 11:46 2006-12-21 Show GitHub Exploit DB Packet Storm
274345 - carsen_klock textsend Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2) success parameter.… NVD-CWE-Other
CVE-2006-6695 2011-03-8 11:46 2006-12-22 Show GitHub Exploit DB Packet Storm
274346 - gnome gconf The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a deni… NVD-CWE-Other
CVE-2006-6698 2011-03-8 11:46 2006-12-23 Show GitHub Exploit DB Packet Storm
274347 - atmail atmail_webmail Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML via crafted e-mail messages. NOTE: The provenance of this in… NVD-CWE-Other
CVE-2006-6702 2011-03-8 11:46 2006-12-23 Show GitHub Exploit DB Packet Storm
274348 - soumu koukyoumuke_soumu_workflow
soumo_workflow
soumu_workflow
Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 a… CWE-287
Improper Authentication
CVE-2006-6705 2011-03-8 11:46 2006-12-23 Show GitHub Exploit DB Packet Storm
274349 - soumu koukyoumuke_soumu_workflow
soumo_workflow
soumu_workflow
SQL injection vulnerability in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allows remote authenticated user… CWE-89
SQL Injection
CVE-2006-6706 2011-03-8 11:46 2006-12-23 Show GitHub Exploit DB Packet Storm
274350 - hitachi hitachi_directory_server_2 Buffer overflow in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allows remote attackers to execute arbitrary code via crafted LDAP requ… NVD-CWE-Other
CVE-2006-6713 2011-03-8 11:46 2006-12-23 Show GitHub Exploit DB Packet Storm