Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 20, 2025, 6:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
311 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2024-46715 2025-01-17 17:12 2024-06-13 Show GitHub Exploit DB Packet Storm
312 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2022-48648 2025-01-17 17:10 2022-09-19 Show GitHub Exploit DB Packet Storm
313 8.8 重要
Network
Huawei EGRT-00 ファームウェア Huawei の EGRT-00 ファームウェアにおける古典的バッファオーバーフローの脆弱性 CWE-119
CWE-120
CVE-2022-48681 2025-01-17 17:07 2024-05-28 Show GitHub Exploit DB Packet Storm
314 4.7 警告
Local
Linux Linux Kernel Linux の Linux Kernel における Time-of-check Time-of-use (TOCTOU) 競合状態の脆弱性 CWE-367
CWE-476
CVE-2024-42107 2025-01-17 17:06 2024-07-3 Show GitHub Exploit DB Packet Storm
315 6.1 警告
Local
Linux Linux Kernel Linux の Linux Kernel における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2023-52497 2025-01-17 17:04 2023-12-15 Show GitHub Exploit DB Packet Storm
316 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows Server 2022
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-362
CWE-843
CVE-2024-49119 2025-01-17 16:59 2024-12-10 Show GitHub Exploit DB Packet Storm
317 9.8 緊急
Network
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Window…
Windows Lightweight Directory Access Protocol (LDAP) のリモートでコードが実行される脆弱性 CWE-190
CWE-noinfo
CVE-2024-49112 2025-01-17 16:55 2024-12-10 Show GitHub Exploit DB Packet Storm
318 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows Server 2022
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-362
CWE-416
CWE-591
CVE-2024-49115 2025-01-17 16:49 2024-12-10 Show GitHub Exploit DB Packet Storm
319 6.4 警告
Local
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows Server 2016
Microsoft Windows 10
Microsoft Windows Server&…
セキュア ブートのセキュリティ機能のバイパスの脆弱性 CWE-190
CWE-noinfo
CVE-2024-28923 2025-01-17 16:46 2024-04-9 Show GitHub Exploit DB Packet Storm
320 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2022-49035 2025-01-17 16:43 2022-09-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 20, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
511 - - - Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private net… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-52602 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
512 - - - OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the org… CWE-287
CWE-284
CWE-285
CWE-269
CWE-272
Improper Authentication
Improper Access Control
Improper Authorization
 Improper Privilege Management
 Least Privilege Violation
CVE-2024-55954 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
513 - - - Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2024-36403 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
514 - - - Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download an… CWE-287
Improper Authentication
CVE-2024-36402 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
515 - - - An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request. - CVE-2024-57684 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
516 - - - Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creatin… - CVE-2025-20630 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
517 - - - Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allo… - CVE-2025-20621 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
518 - - - An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST req… - CVE-2024-57683 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
519 - - - An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST req… - CVE-2024-57682 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm
520 - - - An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request. - CVE-2024-57681 2025-01-17 04:15 2025-01-17 Show GitHub Exploit DB Packet Storm