Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 26, 2025, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
311 9.8 緊急
Network
The Biosig Project
Fedora Project
libbiosig
Fedora
The Biosig Project の libbiosig 等複数ベンダの製品における整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2024-23313 2025-01-23 10:12 2024-02-20 Show GitHub Exploit DB Packet Storm
312 7.8 重要
Local
マイクロソフト Microsoft 365 Apps
Microsoft Office
Microsoft Office のセキュリティ機能のバイパスの脆弱性 CWE-693
CWE-noinfo
CVE-2025-21346 2025-01-22 18:14 2025-01-14 Show GitHub Exploit DB Packet Storm
313 9.8 緊急
Network
The Biosig Project
Fedora Project
libbiosig
Fedora
The Biosig Project の libbiosig 等複数ベンダの製品における境界外書き込みに関する脆弱性 CWE-122
CWE-787
CVE-2024-21795 2025-01-22 18:12 2024-02-20 Show GitHub Exploit DB Packet Storm
314 7.5 重要
Network
マイクロソフト Microsoft Windows 11 Windows Web Threat Defense ユーザー サービスの情報漏えいの脆弱性 CWE-269
CWE-noinfo
CVE-2025-21343 2025-01-22 18:11 2025-01-14 Show GitHub Exploit DB Packet Storm
315 8.8 重要
Network
マイクロソフト Microsoft Windows 11
Microsoft Windows Server 2022
Microsoft Windows Server 2012
Microsoft Windows 10
Microsoft Windows Server&…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21339 2025-01-22 18:06 2025-01-14 Show GitHub Exploit DB Packet Storm
316 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-57896 2025-01-22 18:03 2024-12-6 Show GitHub Exploit DB Packet Storm
317 7.8 重要
Local
Linux Linux Kernel Linux の Linux Kernel における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2024-57892 2025-01-22 18:00 2024-12-30 Show GitHub Exploit DB Packet Storm
318 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2024-57841 2025-01-22 17:57 2024-12-23 Show GitHub Exploit DB Packet Storm
319 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における初期化されていないリソースの使用に関する脆弱性 CWE-908
初期化されていないリソースの使用
CVE-2024-57802 2025-01-22 17:54 2024-12-23 Show GitHub Exploit DB Packet Storm
320 8.8 重要
Network
フォーティネット FortiOS フォーティネットの FortiOS における境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2020-12820 2025-01-22 17:44 2020-09-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 26, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
801 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enguerran Weiss Related Post Shortcode allows Stored XSS. This issue affects Related Post Shortco… CWE-79
Cross-site Scripting
CVE-2025-22276 2025-01-22 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
802 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver … CWE-79
Cross-site Scripting
CVE-2025-22267 2025-01-22 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
803 - - - Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is kn… CWE-330
 Use of Insufficiently Random Values
CVE-2025-22150 2025-01-22 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
804 - - - YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a page or comment to trigger a stored XSS which wil… - CVE-2025-24018 2025-01-22 03:15 2025-01-22 Show GitHub Exploit DB Packet Storm
805 - - - TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg. - CVE-2024-57023 2025-01-22 03:15 2025-01-16 Show GitHub Exploit DB Packet Storm
806 7.5 HIGH
Network
blackberry qnx_software_development_platform Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the imag… CWE-125
Out-of-bounds Read
CVE-2024-48855 2025-01-22 03:07 2025-01-15 Show GitHub Exploit DB Packet Storm
807 7.5 HIGH
Network
blackberry qnx_software_development_platform Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image … CWE-193
 Off-by-one Error
CVE-2024-48854 2025-01-22 03:07 2025-01-15 Show GitHub Exploit DB Packet Storm
808 7.5 HIGH
Network
blackberry qnx_software_development_platform NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using… CWE-476
 NULL Pointer Dereference
CVE-2024-48857 2025-01-22 03:06 2025-01-15 Show GitHub Exploit DB Packet Storm
809 9.8 CRITICAL
Network
blackberry qnx_software_development_platform Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the pr… CWE-787
 Out-of-bounds Write
CVE-2024-48856 2025-01-22 03:06 2025-01-15 Show GitHub Exploit DB Packet Storm
810 7.8 HIGH
Local
adobe substance_3d_designer Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat… CWE-787
 Out-of-bounds Write
CVE-2025-21139 2025-01-22 02:50 2025-01-15 Show GitHub Exploit DB Packet Storm