Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 23, 2025, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
301 7.8 重要
Local
クアルコム WSA8830 ファームウェア
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
 BB) ファームウェア
sc8380xp ファームウェア
WCD9385 ファームウェア
fastconnect …
複数のクアルコム製品における脆弱性 New CWE-284
CWE-Other
CVE-2024-23360 2025-01-21 14:42 2024-06-3 Show GitHub Exploit DB Packet Storm
302 6.3 警告
Network
マイクロソフト Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Server のなりすましの脆弱性 New CWE-79
CWE-noinfo
CVE-2025-21393 2025-01-21 14:30 2025-01-14 Show GitHub Exploit DB Packet Storm
303 5.5 警告
Network
Alex Kirk Friends Alex Kirk の Friends におけるサーバサイドのリクエストフォージェリの脆弱性 New CWE-918
サーバサイドリクエストフォージェリ
CVE-2024-1978 2025-01-21 14:22 2024-02-29 Show GitHub Exploit DB Packet Storm
304 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Office のリモート コードが実行される脆弱性 New CWE-426
CWE-noinfo
CVE-2025-21365 2025-01-21 14:21 2025-01-14 Show GitHub Exploit DB Packet Storm
305 4.3 警告
Network
Really Simple Plugins Complianz - GDPR/CCPA Cookie Consent Complianz の WordPress 用 Complianz - GDPR/CCPA Cookie Consent におけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2024-1592 2025-01-21 14:18 2024-03-2 Show GitHub Exploit DB Packet Storm
306 5 警告
Network
Outlook.com Microsoft Edge Chromium Microsoft Edge (Chrome ベース) のセキュリティ機能のバイパスの脆弱性 New CWE-94
CWE-noinfo
CVE-2024-29991 2025-01-21 14:15 2024-04-19 Show GitHub Exploit DB Packet Storm
307 4.3 警告
Network
フォーティネット FortiOS
FortiProxy
フォーティネットの FortiProxy および FortiOS における脆弱性 New CWE-358
CWE-Other
CVE-2024-33510 2025-01-21 13:55 2024-11-12 Show GitHub Exploit DB Packet Storm
308 6.5 警告
Network
フォーティネット FortiOS フォーティネットの FortiOS における NULL ポインタデリファレンスに関する脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2023-42786 2025-01-21 13:52 2023-09-14 Show GitHub Exploit DB Packet Storm
309 2.7
Network
フォーティネット Fortiweb FortiWebにおけるSQLインジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2024-55593 2025-01-21 12:26 2025-01-21 Show GitHub Exploit DB Packet Storm
310 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server 2016
Microsoft Windows 10
Microsoft Windows Server&…
Win32k の特権の昇格の脆弱性 New CWE-122
CWE-noinfo
CVE-2024-30038 2025-01-21 11:52 2024-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 23, 2025, 5:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
721 - - - The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a vulnerability in handling Modbus messages. When a TCP connection is established with the above series of contro… - CVE-2024-50954 2025-01-18 03:15 2025-01-16 Show GitHub Exploit DB Packet Storm
722 - - - An issue in the dfe_inx_op_col_def_table component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. - CVE-2024-57642 2025-01-18 03:15 2025-01-14 Show GitHub Exploit DB Packet Storm
723 - - - An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. - CVE-2024-57617 2025-01-18 03:15 2025-01-14 Show GitHub Exploit DB Packet Storm
724 - - - An issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. - CVE-2024-57616 2025-01-18 03:15 2025-01-14 Show GitHub Exploit DB Packet Storm
725 - - - An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. - CVE-2024-57615 2025-01-18 03:15 2025-01-14 Show GitHub Exploit DB Packet Storm
726 - - - Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the tr… CWE-77
Command Injection
CVE-2024-54681 2025-01-18 02:15 2025-01-18 Show GitHub Exploit DB Packet Storm
727 - - - A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application b… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2024-53683 2025-01-18 02:15 2025-01-18 Show GitHub Exploit DB Packet Storm
728 - - - Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile application. An att… CWE-798
 Use of Hard-coded Credentials
CVE-2024-45832 2025-01-18 02:15 2025-01-18 Show GitHub Exploit DB Packet Storm
729 - - - All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method under view parameter. The ETIC RAS web serve… CWE-79
Cross-site Scripting
CVE-2024-26157 2025-01-18 02:15 2025-01-18 Show GitHub Exploit DB Packet Storm
730 - - - All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic p… CWE-79
Cross-site Scripting
CVE-2024-26156 2025-01-18 02:15 2025-01-18 Show GitHub Exploit DB Packet Storm