Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
301 7.2 重要
Network
mayurik advocate office management system mayurik の advocate office management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3619 2025-01-29 10:43 2024-04-11 Show GitHub Exploit DB Packet Storm
302 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における例外的な状態のチェックに関する脆弱性 CWE-754
CWE-92
CVE-2024-21809 2025-01-29 10:43 2024-05-16 Show GitHub Exploit DB Packet Storm
303 5.4 警告
Network
Electron Technologies FZC Pagelayer Electron Technologies FZC の WordPress 用 Pagelayer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1590 2025-01-29 10:39 2024-02-23 Show GitHub Exploit DB Packet Storm
304 4.3 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1870 2025-01-29 10:39 2024-03-9 Show GitHub Exploit DB Packet Storm
305 5.5 警告
Local
- IBM の Security Verify Access における初期化されていないリソースの使用に関する脆弱性 CWE-457
CWE-908
CVE-2024-31874 2025-01-29 10:21 2024-04-10 Show GitHub Exploit DB Packet Storm
306 4.9 警告
Network
IBM IBM App Connect Enterprise
IBM Integration Bus
IBM の IBM Integration Bus および IBM App Connect Enterprise におけるエンコードおよびエスケープに関する脆弱性 CWE-116
CWE-117
CVE-2024-22356 2025-01-29 09:57 2024-03-25 Show GitHub Exploit DB Packet Storm
307 7.5 重要
Network
- IBM の Security Verify Access におけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2024-31873 2025-01-29 09:38 2024-04-10 Show GitHub Exploit DB Packet Storm
308 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25946 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
309 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25955 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
310 8.8 重要
Network
UnitedOver Digits UnitedOver の WordPress 用 Digits におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-0203 2025-01-28 18:16 2024-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 13, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1261 - - - ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. - CVE-2024-57097 2025-02-4 06:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1262 - - - In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authe… - CVE-2024-57435 2025-02-4 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1263 - - - macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator. - CVE-2024-57434 2025-02-4 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1264 - - - Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions. - CVE-2024-53320 2025-02-4 06:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1265 - - - Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the server from accepting new DNS-over-QUIC connections by triggering unhandled exce… - CVE-2024-56946 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1266 8.8 HIGH
Network
- - The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2024-12859 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1267 - - - With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. - CVE-2024-12511 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1268 4.3 MEDIUM
Network
- - The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9… CWE-862
 Missing Authorization
CVE-2024-11134 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1269 5.3 MEDIUM
Network
- - The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9… CWE-862
 Missing Authorization
CVE-2024-11133 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1270 6.4 MEDIUM
Network
- - The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user… CWE-79
Cross-site Scripting
CVE-2024-11132 2025-02-4 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm