Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
261 5.4 警告
Network
creativethemes blocksy companion creativethemes の WordPress 用 blocksy companion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4487 2025-01-29 13:46 2024-05-14 Show GitHub Exploit DB Packet Storm
262 8.1 重要
Network
miniOrange Miniorange OTP Verification with Firebase miniOrange の WordPress 用 Miniorange OTP Verification with Firebase における重要な機能に対する認証の欠如に関する脆弱性 CWE-288
CWE-306
CVE-2024-9861 2025-01-29 13:46 2024-10-17 Show GitHub Exploit DB Packet Storm
263 5.5 警告
Local
デル Dell Grab デルの Windows 用 Dell Grab におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2024-25957 2025-01-29 12:07 2024-03-26 Show GitHub Exploit DB Packet Storm
264 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3989 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
265 5.4 警告
Network
creativethemes blocksy creativethemes の WordPress 用 blocksy におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4158 2025-01-29 11:46 2024-05-14 Show GitHub Exploit DB Packet Storm
266 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21777 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
267 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21862 2025-01-29 11:46 2024-05-16 Show GitHub Exploit DB Packet Storm
268 9.8 緊急
Network
クアルコム (複数の製品) キヤノン製スモールオフィス向け複合機およびレーザービームプリンターにおける複数の境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2024-12647
CVE-2024-12648
CVE-2024-12649
2025-01-29 11:42 2025-01-28 Show GitHub Exploit DB Packet Storm
269 5.4 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3337 2025-01-29 11:42 2024-05-2 Show GitHub Exploit DB Packet Storm
270 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-25151 2025-01-29 11:42 2024-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 7, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
951 - - - RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted… - CVE-2024-57436 2025-01-30 00:15 2025-01-30 Show GitHub Exploit DB Packet Storm
952 - - - Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Mediu… CWE-416
 Use After Free
CVE-2025-0762 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
953 - - - The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again… - CVE-2024-12749 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
954 - - - A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of the argument flowId leads to sql in… - CVE-2025-0792 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
955 - - - A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId… - CVE-2025-0791 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
956 - - - A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The manipulation of the argument curpage leads to cross si… - CVE-2025-0790 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
957 - - - A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the argument flowId leads to sql injection. It … - CVE-2025-0789 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
958 - - - A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /content_top.jsp. The manipulation of the argument id lea… - CVE-2025-0788 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
959 - - - An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file. - CVE-2024-57519 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm
960 - - - Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs i… - CVE-2024-56529 2025-01-30 00:15 2025-01-29 Show GitHub Exploit DB Packet Storm