Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 14, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
281 9.8 緊急
Network
クアルコム SD 210 ファームウェア
SD 845 ファームウェア
SD 625 ファームウェア
SD 616 ファームウェア
MSM8996AU ファームウェア
SD 427 ファームウェア
MSM8909W ファームウェア
SD …
複数のクアルコム製品におけるバッファエラーの脆弱性 CWE-119
CWE-823
CVE-2017-11076 2025-01-10 16:28 2017-07-7 Show GitHub Exploit DB Packet Storm
282 7.2 重要
Network
PaperCut Software International Pty PaperCut NG PaperCut Software International Pty の PaperCut NG における脆弱性 CWE-749
CWE-Other
CVE-2023-39470 2025-01-10 16:28 2023-08-2 Show GitHub Exploit DB Packet Storm
283 4.8 警告
Network
ThimPress LearnPress ThimPress の WordPress 用 LearnPress におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1463 2025-01-10 16:28 2024-04-9 Show GitHub Exploit DB Packet Storm
284 5.3 警告
Network
Eclipse Foundation eclipse dataspace components Eclipse Foundation の eclipse dataspace components における認証の欠如に関する脆弱性 CWE-862
CWE-862
CVE-2024-9202 2025-01-10 16:28 2024-09-27 Show GitHub Exploit DB Packet Storm
285 7.5 重要
Network
クアルコム fastconnect 6900 ファームウェア
ipq5312 ファームウェア
CSR8811 ファームウェア
immersive home 214 ファームウェア
fastconnect 7800 ファームウェア
IPQ6000 ファームウェア
IPQ501…
複数のクアルコム製品における境界外読み取りに関する脆弱性 CWE-125
CWE-126
CVE-2024-23363 2025-01-10 16:28 2024-06-3 Show GitHub Exploit DB Packet Storm
286 6 警告
Local
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS におけるリンク解釈に関する脆弱性 CWE-59
CWE-61
CVE-2024-25953 2025-01-10 16:28 2024-03-28 Show GitHub Exploit DB Packet Storm
287 6.7 警告
Local
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS における脆弱性 CWE-269
CWE-noinfo
CVE-2024-25961 2025-01-10 16:28 2024-03-28 Show GitHub Exploit DB Packet Storm
288 7.5 重要
Network
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS における脆弱性 CWE-385
CWE-Other
CVE-2024-25964 2025-01-10 16:28 2024-03-25 Show GitHub Exploit DB Packet Storm
289 7.5 重要
Network
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS における脆弱性 CWE-241
CWE-Other
CVE-2024-25966 2025-01-10 16:28 2024-05-14 Show GitHub Exploit DB Packet Storm
290 6.5 警告
Network
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS における脆弱性 CWE-20
CWE-noinfo
CVE-2024-25970 2025-01-10 16:28 2024-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 15, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
191 - - - SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to … New CWE-94
Code Injection
CVE-2025-0060 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
192 - - - Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or acces… New CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-0059 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
193 - - - WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `cadastro_funcionar… New CWE-79
Cross-site Scripting
CVE-2025-23030 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
194 - - - In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwis… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-0058 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
195 - - - SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim v… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-0057 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
196 - - - SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim?s user directory on the Operating System level would be abl… New CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-0056 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
197 - - - SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim?s user directory on t… New CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2025-0055 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
198 - - - SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could … New CWE-209
Information Exposure Through an Error Message
CVE-2025-0053 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
199 - - - An issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. New - CVE-2024-57664 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
200 - - - An issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. New - CVE-2024-57663 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm