Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 15, 2025, 6:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
331 5.5 警告
Local
クアルコム WCD9385 ファームウェア
fastconnect 6700 ファームウェア
fastconnect 7800 ファームウェア
wsa8845 ファームウェア
wsa8840 ファームウェア
sc8380xp ファームウェア
WSA8830 ファームウェア
sn…
複数のクアルコム製品における境界外読み取りに関する脆弱性 New CWE-125
CWE-126
CVE-2023-33078 2025-01-14 13:35 2023-05-17 Show GitHub Exploit DB Packet Storm
332 5.3 警告
Network
IBM IBM CICS TX IBM の IBM CICS TX における観測可能な不一致に関する脆弱性 New CWE-203
CWE-204
CVE-2023-38362 2025-01-14 13:30 2023-11-3 Show GitHub Exploit DB Packet Storm
333 6.5 警告
Network
Mozilla Foundation Mozilla Firefox Mozilla Foundation の Mozilla Firefox における脆弱性 New CWE-Other
その他
CVE-2024-10941 2025-01-14 13:22 2024-05-14 Show GitHub Exploit DB Packet Storm
334 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft OLE DB Driver
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 New CWE-122
CWE-noinfo
CVE-2024-28912 2025-01-14 13:22 2024-04-9 Show GitHub Exploit DB Packet Storm
335 7.2 重要
Network
マイクロソフト Azure Database for PostgreSQL Flexible Server Azure Database for PostgreSQL フレキシブル サーバー拡張機能の特権昇格の脆弱性 New CWE-77
CWE-noinfo
CVE-2024-43613 2025-01-14 13:22 2024-11-12 Show GitHub Exploit DB Packet Storm
336 6.2 警告
Adjacent
マイクロソフト Azure Arc Cluster microsoft.azure.hybridnetwork Extension
Azure Arc Cluster microsoft.azstackhci.operator Extension
Azure Arc Cluster micr…
Azure Arc 対応 Kubernetes 拡張機能クラスタースコープの特権昇格の脆弱性 New CWE-284
CWE-noinfo
CVE-2024-28917 2025-01-14 13:22 2024-04-9 Show GitHub Exploit DB Packet Storm
337 4.6 警告
Physics
Linux Linux Kernel Linux の Linux Kernel における境界条件の判定に関する脆弱性 New CWE-193
境界条件の判定
CVE-2024-53149 2025-01-14 12:04 2024-11-10 Show GitHub Exploit DB Packet Storm
338 5.3 警告
Network
Huawei USG6000V ファームウェア
NGFW Module ファームウェア
Secospace USG6600 ファームウェア
NIP6800 ファームウェア
Secospace USG6500 ファームウェア
NIP6300 ファームウェア
IPS Module…
複数の Huawei 製品における境界外読み取りに関する脆弱性 New CWE-125
CWE-125
CVE-2020-1819 2025-01-14 11:48 2024-12-27 Show GitHub Exploit DB Packet Storm
339 4.3 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2021-4446 2025-01-14 11:48 2024-10-16 Show GitHub Exploit DB Packet Storm
340 7.5 重要
Network
クアルコム CSRB31024 ファームウェア
AR8035 ファームウェア
fastconnect 6900 ファームウェア
QCA6391 ファームウェア
QCA6564AU ファームウェア
fastconnect 6700 ファームウェア
QCA6426 ファームウェア
複数のクアルコム製品における有効期限後のメモリの解放の欠如に関する脆弱性 New CWE-401
CWE-401
CVE-2023-33086 2025-01-14 11:48 2023-05-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 15, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
171 8.5 HIGH
Network
- - The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. … New CWE-862
 Missing Authorization
CVE-2024-12365 2025-01-14 16:15 2025-01-14 Show GitHub Exploit DB Packet Storm
172 6.4 MEDIUM
Network
- - The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input s… New CWE-79
Cross-site Scripting
CVE-2024-13323 2025-01-14 15:15 2025-01-14 Show GitHub Exploit DB Packet Storm
173 6.1 MEDIUM
Network
- - The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce … New CWE-352
 Origin Validation Error
CVE-2024-13348 2025-01-14 13:15 2025-01-14 Show GitHub Exploit DB Packet Storm
174 8.8 HIGH
Network
- - An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allo… New CWE-269
 Improper Privilege Management
CVE-2024-12398 2025-01-14 11:15 2025-01-14 Show GitHub Exploit DB Packet Storm
175 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid… New - CVE-2024-11637 2025-01-14 11:15 2025-01-14 Show GitHub Exploit DB Packet Storm
176 - - - WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `remuneracao.php` endp… New CWE-79
Cross-site Scripting
CVE-2025-23038 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
177 - - - WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint… New CWE-79
Cross-site Scripting
CVE-2025-23037 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
178 - - - WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `pre_cadastro_funci… New CWE-79
Cross-site Scripting
CVE-2025-23036 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
179 - - - SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in pri… New CWE-287
Improper Authentication
CVE-2025-0070 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm
180 - - - Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user?s Windows account could gain higher privileges. With this,… New CWE-427
 Uncontrolled Search Path Element
CVE-2025-0069 2025-01-14 10:15 2025-01-14 Show GitHub Exploit DB Packet Storm