Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
301 7.2 重要
Network
mayurik advocate office management system mayurik の advocate office management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3619 2025-01-29 10:43 2024-04-11 Show GitHub Exploit DB Packet Storm
302 7.3 重要
Local
インテル Quartus Prime インテルの Quartus Prime における例外的な状態のチェックに関する脆弱性 CWE-754
CWE-92
CVE-2024-21809 2025-01-29 10:43 2024-05-16 Show GitHub Exploit DB Packet Storm
303 5.4 警告
Network
Electron Technologies FZC Pagelayer Electron Technologies FZC の WordPress 用 Pagelayer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1590 2025-01-29 10:39 2024-02-23 Show GitHub Exploit DB Packet Storm
304 4.3 警告
Network
Extend Themes colibri page builder Extend Themes の WordPress 用 colibri page builder における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1870 2025-01-29 10:39 2024-03-9 Show GitHub Exploit DB Packet Storm
305 5.5 警告
Local
- IBM の Security Verify Access における初期化されていないリソースの使用に関する脆弱性 CWE-457
CWE-908
CVE-2024-31874 2025-01-29 10:21 2024-04-10 Show GitHub Exploit DB Packet Storm
306 4.9 警告
Network
IBM IBM App Connect Enterprise
IBM Integration Bus
IBM の IBM Integration Bus および IBM App Connect Enterprise におけるエンコードおよびエスケープに関する脆弱性 CWE-116
CWE-117
CVE-2024-22356 2025-01-29 09:57 2024-03-25 Show GitHub Exploit DB Packet Storm
307 7.5 重要
Network
- IBM の Security Verify Access におけるハードコードされた認証情報の使用に関する脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2024-31873 2025-01-29 09:38 2024-04-10 Show GitHub Exploit DB Packet Storm
308 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25946 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
309 8.8 重要
Network
デル Dell PowerMax EEM
Solutions Enabler Virtual Appliance
Dell Unisphere for PowerMax Virtual Appliance
複数のデル製品におけるコマンドインジェクションの脆弱性 CWE-77
CWE-78
CVE-2024-25955 2025-01-28 18:22 2024-03-28 Show GitHub Exploit DB Packet Storm
310 8.8 重要
Network
UnitedOver Digits UnitedOver の WordPress 用 Digits におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-0203 2025-01-28 18:16 2024-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 23, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
279751 - inso dwhttpd AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length. NVD-CWE-Other
CVE-1999-1416 2008-09-11 04:01 1998-08-23 Show GitHub Exploit DB Packet Storm
279752 - inso answerbook2 Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an H… NVD-CWE-Other
CVE-1999-1417 2008-09-11 04:01 1998-08-23 Show GitHub Exploit DB Packet Storm
279753 - computer_software_manufaktur alibaba genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. NVD-CWE-Other
CVE-1999-1444 2008-09-11 04:01 1999-12-31 Show GitHub Exploit DB Packet Storm
279754 - sco openserver
unixware
Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges. NVD-CWE-Other
CVE-1999-1450 2008-09-11 04:01 1999-01-27 Show GitHub Exploit DB Packet Storm
279755 - thttpd thttpd_http_server Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function. NVD-CWE-Other
CVE-1999-1457 2008-09-11 04:01 1999-11-16 Show GitHub Exploit DB Packet Storm
279756 - next
sgi
cray
sun
next
irix
unicos
sunos
rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable. NVD-CWE-Other
CVE-1999-1468 2008-09-11 04:01 1991-10-22 Show GitHub Exploit DB Packet Storm
279757 - sun java Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Tro… CWE-94
Code Injection
CVE-2008-3440 2008-09-10 13:00 2008-08-1 Show GitHub Exploit DB Packet Storm
279758 - ignite_realtime openfire The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute… CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-2975 2008-09-10 13:00 2007-06-1 Show GitHub Exploit DB Packet Storm
279759 - ignite_realtime openfire The vendor has addressed this issue through the release of the following product updates: Ignite Realtime openfire-3.3.1-1.i386.rpm http://www.igniterealtime.org/downloads/download-landing.jsp?fi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-2975 2008-09-10 13:00 2007-06-1 Show GitHub Exploit DB Packet Storm
279760 - oracle oracle8i
oracle9i
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible. CWE-94
Code Injection
CVE-2004-0637 2008-09-10 13:00 2004-09-2 Show GitHub Exploit DB Packet Storm