Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 18, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
271 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における二重解放に関する脆弱性 New CWE-415
二重解放
CVE-2024-36973 2025-01-16 17:40 2024-06-4 Show GitHub Exploit DB Packet Storm
272 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel におけるリソースのロックに関する脆弱性 New CWE-667
不適切なロック
CVE-2024-35998 2025-01-16 17:38 2024-04-25 Show GitHub Exploit DB Packet Storm
273 6.5 警告
Network
VillaTheme Thank You Page Customizer for WooCommerce - Increase Your Sales VillaTheme の WordPress 用 Thank You Page Customizer for WooCommerce - Increase Your Sales における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-1686 2025-01-16 17:31 2024-02-27 Show GitHub Exploit DB Packet Storm
274 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2023-52837 2025-01-16 17:27 2023-11-7 Show GitHub Exploit DB Packet Storm
275 8.8 重要
Network
マイクロソフト Microsoft Visual Studio
Microsoft SQL Server
Microsoft ODBC Driver
SQL Server 用 Microsoft ODBC ドライバーのリモートでコードが実行される脆弱性 New CWE-125
CWE-noinfo
CVE-2024-28938 2025-01-16 17:26 2024-04-9 Show GitHub Exploit DB Packet Storm
276 7.5 重要
Network
クアルコム QCA6584AU ファームウェア
fastconnect 7800 ファームウェア
qcm8550 ファームウェア
fastconnect 6900 ファームウェア
qcn9024 ファームウェア
qcc710 ファームウェア
qcm4490 ファームウェア
fa…
複数のクアルコム製品における脆弱性 New CWE-20
CWE-noinfo
CVE-2023-33100 2025-01-16 17:25 2023-05-17 Show GitHub Exploit DB Packet Storm
277 7.8 重要
Local
クアルコム fastconnect 7800 ファームウェア
fastconnect 6800 ファームウェア
fastconnect 6900 ファームウェア
AQT1000 ファームウェア
flight rb5 5g ファームウェア
fastconnect 6700…
複数のクアルコム製品における解放済みメモリの使用に関する脆弱性 New CWE-416
CWE-416
CVE-2024-21468 2025-01-16 17:25 2024-04-1 Show GitHub Exploit DB Packet Storm
278 6.5 警告
Network
Synology Inc. Surveillance Station Synology Inc. の Surveillance Station における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-29240 2025-01-16 17:25 2024-03-28 Show GitHub Exploit DB Packet Storm
279 7.8 重要
Local
クアルコム QCA6584AU ファームウェア
QCA6391 ファームウェア
qamsrv1h ファームウェア
fastconnect 7800 ファームウェア
fastconnect 6900 ファームウェア
flight rb5 5g ファームウェア
QCA6574A…
複数のクアルコム製品における解放済みメモリの使用に関する脆弱性 New CWE-416
解放済みメモリの使用
CVE-2024-45553 2025-01-16 17:25 2024-09-2 Show GitHub Exploit DB Packet Storm
280 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2021-47463 2025-01-16 17:25 2021-10-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
431 - - - A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.… New CWE-22
Path Traversal
CVE-2024-48885 2025-01-16 18:15 2025-01-16 Show GitHub Exploit DB Packet Storm
432 - - - A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.… New CWE-266
 Incorrect Privilege Assignment
CVE-2024-45331 2025-01-16 18:15 2025-01-16 Show GitHub Exploit DB Packet Storm
433 - - - In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was de… New - CVE-2024-12226 2025-01-16 16:15 2025-01-16 Show GitHub Exploit DB Packet Storm
434 6.4 MEDIUM
Network
- - The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8… New CWE-79
Cross-site Scripting
CVE-2024-11452 2025-01-16 13:15 2025-01-16 Show GitHub Exploit DB Packet Storm
435 4.3 MEDIUM
Network
- - The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wp… New CWE-352
 Origin Validation Error
CVE-2024-10789 2025-01-16 13:15 2025-01-16 Show GitHub Exploit DB Packet Storm
436 - - - RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function. New - CVE-2025-22904 2025-01-16 12:15 2025-01-16 Show GitHub Exploit DB Packet Storm
437 8.8 HIGH
Network
- - The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. New CWE-78
OS Command 
CVE-2025-0457 2025-01-16 11:15 2025-01-16 Show GitHub Exploit DB Packet Storm
438 9.8 CRITICAL
Network
- - The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all acco… New CWE-306
Missing Authentication for Critical Function
CVE-2025-0456 2025-01-16 11:15 2025-01-16 Show GitHub Exploit DB Packet Storm
439 9.8 CRITICAL
Network
- - The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. New CWE-89
SQL Injection
CVE-2025-0455 2025-01-16 11:15 2025-01-16 Show GitHub Exploit DB Packet Storm
440 6.1 MEDIUM
Network
- - The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on the… New CWE-79
Cross-site Scripting
CVE-2025-0170 2025-01-16 11:15 2025-01-16 Show GitHub Exploit DB Packet Storm