Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
301 7.2 重要
Network
mayurik advocate office management system mayurik の advocate office management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3619 2025-01-29 10:43 2024-04-11 Show GitHub Exploit DB Packet Storm
302 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における例外的な状態のチェックに関する脆弱性 CWE-754
CWE-92
CVE-2024-21809 2025-01-29 10:43 2024-05-16 Show GitHub Exploit DB Packet Storm
303 5.4 警告
Network
Electron Technologies FZC Pagelayer Electron Technologies FZC の WordPress 用 Pagelayer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1590 2025-01-29 10:39 2024-02-23 Show GitHub Exploit DB Packet Storm
304 4.3 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1870 2025-01-29 10:39 2024-03-9 Show GitHub Exploit DB Packet Storm
305 5.5 警告
Local
- IBM の Security Verify Access における初期化されていないリソースの使用に関する脆弱性 CWE-457
CWE-908
CVE-2024-31874 2025-01-29 10:21 2024-04-10 Show GitHub Exploit DB Packet Storm
306 4.9 警告
Network
IBM IBM App Connect Enterprise
IBM Integration Bus
IBM の IBM Integration Bus および IBM App Connect Enterprise におけるエンコードおよびエスケープに関する脆弱性 CWE-116
CWE-117
CVE-2024-22356 2025-01-29 09:57 2024-03-25 Show GitHub Exploit DB Packet Storm
307 7.5 重要
Network
- IBM の Security Verify Access におけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2024-31873 2025-01-29 09:38 2024-04-10 Show GitHub Exploit DB Packet Storm
308 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25946 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
309 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25955 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
310 8.8 重要
Network
UnitedOver Digits UnitedOver の WordPress 用 Digits におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-0203 2025-01-28 18:16 2024-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 4, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274511 - greywyvern orca_blog SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter. NVD-CWE-Other
CVE-2005-3941 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274512 - greywyvern orca_knowledgebase SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter. NVD-CWE-Other
CVE-2005-3942 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274513 - - - Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; a… NVD-CWE-Other
CVE-2005-3943 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274514 - faq_system faq_system SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter. NVD-CWE-Other
CVE-2005-3944 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274515 - nufw nufw nuauth in NuFW 1.0.x before 1.0.16 and 1.1 allows authenticated users to cause a denial of service via malformed packets. NVD-CWE-Other
CVE-2005-3950 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274516 - php_labs survey_wizard SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter. NVD-CWE-Other
CVE-2005-3951 2011-03-8 11:27 2005-12-1 Show GitHub Exploit DB Packet Storm
274517 - java_search_engine java_search_engine Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NVD-CWE-Other
CVE-2005-3966 2011-03-8 11:27 2005-12-4 Show GitHub Exploit DB Packet Storm
274518 - atlassian confluence Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.q… NVD-CWE-Other
CVE-2005-3967 2011-03-8 11:27 2005-12-4 Show GitHub Exploit DB Packet Storm
274519 - mxchange mxchange SQL injection vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NVD-CWE-Other
CVE-2005-3969 2011-03-8 11:27 2005-12-4 Show GitHub Exploit DB Packet Storm
274520 - mxchange mxchange Cross-site scripting (XSS) vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NVD-CWE-Other
CVE-2005-3970 2011-03-8 11:27 2005-12-4 Show GitHub Exploit DB Packet Storm