Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 11, 2025, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
281 9.8 緊急
Network
Xerox freeflow core Xerox の freeflow core におけるパストラバーサルの脆弱性 Update CWE-22
CWE-22
CVE-2024-47557 2025-01-9 14:37 2024-10-7 Show GitHub Exploit DB Packet Storm
282 9.8 緊急
Network
Xerox freeflow core Xerox の freeflow core におけるパストラバーサルの脆弱性 Update CWE-22
CWE-22
CVE-2024-47556 2025-01-9 14:36 2024-10-7 Show GitHub Exploit DB Packet Storm
283 8.8 重要
Network
Xerox freeflow core Xerox の freeflow core におけるパストラバーサルの脆弱性 Update CWE-22
CWE-22
CVE-2024-47559 2025-01-9 14:35 2024-10-7 Show GitHub Exploit DB Packet Storm
284 - - Nedap Librix Ecoreader Nedap Librix 製 Ecoreader における重要な機能に対する認証の欠如の脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2024-12757 2025-01-9 13:55 2025-01-8 Show GitHub Exploit DB Packet Storm
285 6.5 警告
Network
IBM IBM App Connect Enterprise IBM の IBM App Connect Enterprise における有効期限後または解放後のリソースの操作に関する脆弱性 New CWE-324
CWE-672
CVE-2024-31895 2025-01-9 11:26 2024-05-21 Show GitHub Exploit DB Packet Storm
286 5.4 警告
Network
IBM IBM Planning Analytics Local IBM の IBM Planning Analytics Local におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-31908 2025-01-9 11:26 2024-05-30 Show GitHub Exploit DB Packet Storm
287 4.3 警告
Network
Frenify Categorify - WordPress Media Library Category & File Manager Frenify の WordPress 用 Categorify - WordPress Media Library Category & File Manager における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-0385 2025-01-9 11:24 2024-03-13 Show GitHub Exploit DB Packet Storm
288 4.3 警告
Network
Royal Elementor Addons Royal Elementor Addons and Templates Royal Elementor Addons の WordPress 用 Royal Elementor Addons and Templates におけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2024-0515 2025-01-9 11:24 2024-02-29 Show GitHub Exploit DB Packet Storm
289 6.5 警告
Network
mintplexlabs anythingllm mintplexlabs の anythingllm における情報漏えいに関する脆弱性 New CWE-200
情報漏えい
CVE-2024-0765 2025-01-9 11:24 2024-03-3 Show GitHub Exploit DB Packet Storm
290 5.4 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1172 2025-01-9 11:24 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 11, 2025, 5:03 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1 7.8 HIGH
Local
qualcomm fastconnect_6900_firmware
fastconnect_7800_firmware
qcm8550_firmware
qcs8550_firmware
sg8275p_firmware
sm8550p_firmware
snapdragon_8_gen_2_mobile_firmware
snapdragon_8_gen_3_mobi…
Memory corruption while processing frame command IOCTL calls. Update CWE-416
 Use After Free
CVE-2024-33059 2025-01-11 01:53 2025-01-6 Show GitHub Exploit DB Packet Storm
2 5.5 MEDIUM
Local
qualcomm qcs8550_firmware
sw5100_firmware
sw5100p_firmware
wcn3660b_firmware
wcn3680b_firmware
wcn3980_firmware
wcn3988_firmware
wsa8830_firmware
wsa8835_firmware
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process. Update CWE-125
Out-of-bounds Read
CVE-2024-33061 2025-01-11 01:49 2025-01-6 Show GitHub Exploit DB Packet Storm
3 - - - Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution. New - CVE-2025-22949 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
4 - - - WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerab… New CWE-79
Cross-site Scripting
CVE-2025-22600 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
5 - - - WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows at… New CWE-79
Cross-site Scripting
CVE-2025-22599 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
6 - - - WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability al… New CWE-79
Cross-site Scripting
CVE-2025-22598 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
7 - - - WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerabilit… New CWE-79
Cross-site Scripting
CVE-2025-22597 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
8 - - - WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This vulnerabili… New CWE-79
Cross-site Scripting
CVE-2025-22596 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
9 - - - Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execut… New CWE-22
CWE-94
CWE-434
Path Traversal
Code Injection
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-22152 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm
10 - - - DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause t… New CWE-289
 Authentication Bypass by Alternate Name
CVE-2024-56511 2025-01-11 01:15 2025-01-11 Show GitHub Exploit DB Packet Storm