Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
281 8.1 重要
Network
GLPI-PROJECT.ORG GLPI GLPI-PROJECT.ORG の GLPI における SQL インジェクションの脆弱性 CWE-89
CWE-89
CVE-2024-29889 2025-01-29 10:59 2024-05-7 Show GitHub Exploit DB Packet Storm
282 7.3 重要
Local
インテル Intel Driver and Support Assistant インテルの Intel Driver and Support Assistant における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2023-45743 2025-01-29 10:54 2023-10-12 Show GitHub Exploit DB Packet Storm
283 6.1 警告
Network
Incsub forminator Incsub の WordPress 用 forminator におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1794 2025-01-29 10:54 2024-04-9 Show GitHub Exploit DB Packet Storm
284 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2085 2025-01-29 10:54 2024-05-2 Show GitHub Exploit DB Packet Storm
285 6.4 警告
Network
POSIMYTH The Plus Addons for Elementor Page Builder POSIMYTH の WordPress 用 The Plus Addons for Elementor Page Builder における脆弱性 CWE-noinfo
情報不足
CVE-2024-2210 2025-01-29 10:54 2024-03-27 Show GitHub Exploit DB Packet Storm
286 5.4 警告
Network
wpthemespace magical addons for elementor wpthemespace の WordPress 用 magical addons for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2923 2025-01-29 10:54 2024-05-14 Show GitHub Exploit DB Packet Storm
287 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-5215 2025-01-29 10:54 2024-06-26 Show GitHub Exploit DB Packet Storm
288 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における制御されていない検索パスの要素に関する脆弱性 CWE-427
CWE-427
CVE-2024-21837 2025-01-29 10:54 2024-05-16 Show GitHub Exploit DB Packet Storm
289 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-25602 2025-01-29 10:54 2024-02-21 Show GitHub Exploit DB Packet Storm
290 5.4 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Liferay Portal および Digital Experience Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-26266 2025-01-29 10:54 2024-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 8, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1031 - - - The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. - CVE-2024-12709 2025-01-31 01:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1032 - - - The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow … - CVE-2024-12708 2025-01-31 01:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1033 - - - The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against h… - CVE-2024-12638 2025-01-31 01:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1034 - - - The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. - CVE-2024-12400 2025-01-31 01:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1035 - - - The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. - CVE-2024-12163 2025-01-31 01:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1036 - - - VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated… - CVE-2025-22218 2025-01-31 00:15 2025-01-31 Show GitHub Exploit DB Packet Storm
1037 3.5 LOW
Network
- - A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. The manipulation of… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0871 2025-01-31 00:15 2025-01-31 Show GitHub Exploit DB Packet Storm
1038 4.3 MEDIUM
Network
- - The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' shortcode. This makes… CWE-200
Information Exposure
CVE-2024-8494 2025-01-30 23:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1039 9.8 CRITICAL
Network
- - The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the… CWE-502
 Deserialization of Untrusted Data
CVE-2024-13742 2025-01-30 23:15 2025-01-30 Show GitHub Exploit DB Packet Storm
1040 8.8 HIGH
Network
- - The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, … CWE-352
 Origin Validation Error
CVE-2024-13720 2025-01-30 23:15 2025-01-30 Show GitHub Exploit DB Packet Storm