Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 15, 2025, 6:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
331 5.5 警告
Local
クアルコム WCD9385 ファームウェア
fastconnect 6700 ファームウェア
fastconnect 7800 ファームウェア
wsa8845 ファームウェア
wsa8840 ファームウェア
sc8380xp ファームウェア
WSA8830 ファームウェア
sn…
複数のクアルコム製品における境界外読み取りに関する脆弱性 New CWE-125
CWE-126
CVE-2023-33078 2025-01-14 13:35 2023-05-17 Show GitHub Exploit DB Packet Storm
332 5.3 警告
Network
IBM IBM CICS TX IBM の IBM CICS TX における観測可能な不一致に関する脆弱性 New CWE-203
CWE-204
CVE-2023-38362 2025-01-14 13:30 2023-11-3 Show GitHub Exploit DB Packet Storm
333 6.5 警告
Network
Mozilla Foundation Mozilla Firefox Mozilla Foundation の Mozilla Firefox における脆弱性 New CWE-Other
その他
CVE-2024-10941 2025-01-14 13:22 2024-05-14 Show GitHub Exploit DB Packet Storm
334 8.8 重要
Network
マイクロソフト Microsoft SQL Server
Microsoft OLE DB Driver
SQL Server 用 Microsoft OLE DB ドライバーのリモートでコードが実行される脆弱性 New CWE-122
CWE-noinfo
CVE-2024-28912 2025-01-14 13:22 2024-04-9 Show GitHub Exploit DB Packet Storm
335 7.2 重要
Network
マイクロソフト Azure Database for PostgreSQL Flexible Server Azure Database for PostgreSQL フレキシブル サーバー拡張機能の特権昇格の脆弱性 New CWE-77
CWE-noinfo
CVE-2024-43613 2025-01-14 13:22 2024-11-12 Show GitHub Exploit DB Packet Storm
336 6.2 警告
Adjacent
マイクロソフト Azure Arc Cluster microsoft.azure.hybridnetwork Extension
Azure Arc Cluster microsoft.azstackhci.operator Extension
Azure Arc Cluster micr…
Azure Arc 対応 Kubernetes 拡張機能クラスタースコープの特権昇格の脆弱性 New CWE-284
CWE-noinfo
CVE-2024-28917 2025-01-14 13:22 2024-04-9 Show GitHub Exploit DB Packet Storm
337 4.6 警告
Physics
Linux Linux Kernel Linux の Linux Kernel における境界条件の判定に関する脆弱性 New CWE-193
境界条件の判定
CVE-2024-53149 2025-01-14 12:04 2024-11-10 Show GitHub Exploit DB Packet Storm
338 5.3 警告
Network
Huawei USG6000V ファームウェア
NGFW Module ファームウェア
Secospace USG6600 ファームウェア
NIP6800 ファームウェア
Secospace USG6500 ファームウェア
NIP6300 ファームウェア
IPS Module…
複数の Huawei 製品における境界外読み取りに関する脆弱性 New CWE-125
CWE-125
CVE-2020-1819 2025-01-14 11:48 2024-12-27 Show GitHub Exploit DB Packet Storm
339 4.3 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2021-4446 2025-01-14 11:48 2024-10-16 Show GitHub Exploit DB Packet Storm
340 7.5 重要
Network
クアルコム CSRB31024 ファームウェア
AR8035 ファームウェア
fastconnect 6900 ファームウェア
QCA6391 ファームウェア
QCA6564AU ファームウェア
fastconnect 6700 ファームウェア
QCA6426 ファームウェア
複数のクアルコム製品における有効期限後のメモリの解放の欠如に関する脆弱性 New CWE-401
CWE-401
CVE-2023-33086 2025-01-14 11:48 2023-05-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 15, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278261 - fascript faname class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installatio… CWE-200
Information Exposure
CVE-2007-3651 2008-09-5 13:00 2008-07-9 Show GitHub Exploit DB Packet Storm
278262 - fascript faname SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same i… CWE-89
SQL Injection
CVE-2007-3652 2008-09-5 13:00 2008-07-9 Show GitHub Exploit DB Packet Storm
278263 - dirlist dirlist_php Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot) in the folder param… CWE-22
Path Traversal
CVE-2007-3967 2008-09-5 13:00 2007-07-26 Show GitHub Exploit DB Packet Storm
278264 - dirlist dirlist_php index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name. CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-3968 2008-09-5 13:00 2007-07-26 Show GitHub Exploit DB Packet Storm
278265 - mozilla mozilla Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metac… CWE-79
Cross-site Scripting
CVE-2007-4039 2008-09-5 13:00 2007-07-28 Show GitHub Exploit DB Packet Storm
278266 - microsoft outlook
outlook_express
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbi… CWE-79
Cross-site Scripting
CVE-2007-4040 2008-09-5 13:00 2007-07-28 Show GitHub Exploit DB Packet Storm
278267 - securecomputing securityreporter file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE… CWE-287
Improper Authentication
CVE-2007-4043 2008-09-5 13:00 2007-07-28 Show GitHub Exploit DB Packet Storm
278268 - bitdefender antivirus
internet_security
total_security
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory wit… NVD-CWE-noinfo
CVE-2007-5775 2008-09-5 13:00 2007-11-2 Show GitHub Exploit DB Packet Storm
278269 - contentcustomizer contentcustomizer dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. NOTE: this issue can be leve… CWE-79
Cross-site Scripting
CVE-2007-5817 2008-09-5 13:00 2007-11-6 Show GitHub Exploit DB Packet Storm
278270 - openbase_international_ltd openbase Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog st… CWE-22
Path Traversal
CVE-2007-5927 2008-09-5 13:00 2007-11-10 Show GitHub Exploit DB Packet Storm