Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 20, 2025, 6:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
421 8.8 重要
Network
Brizy brizy Brizy の WordPress 用 brizy における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2024-1311 2025-01-17 11:58 2024-03-13 Show GitHub Exploit DB Packet Storm
422 5.3 警告
Network
zestard admin side data storage for contact form 7 zestard の WordPress 用 admin side data storage for contact form 7 における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-1779 2025-01-17 11:58 2024-02-23 Show GitHub Exploit DB Packet Storm
423 8.8 重要
Network
Progress Software Corporation telerik report server Progress Software Corporation の telerik report server における信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
CWE-502
CVE-2024-1800 2025-01-17 11:58 2024-03-20 Show GitHub Exploit DB Packet Storm
424 7.5 重要
Network
Ivanti Avalanche Ivanti の Avalanche におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2024-13180 2025-01-17 11:58 2025-01-14 Show GitHub Exploit DB Packet Storm
425 - - Belledonne Communications Linphone-Desktop Belledonne Communications 製 Linphone-Desktop における NULL ポインタ参照の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2025-0430 2025-01-17 11:56 2025-01-16 Show GitHub Exploit DB Packet Storm
426 9.8 緊急
Network
Apache Software Foundation hertzbeat Apache Software Foundation の hertzbeat におけるインジェクションに関する脆弱性 CWE-74
CWE-74
CVE-2023-51653 2025-01-17 11:54 2023-12-20 Show GitHub Exploit DB Packet Storm
427 7.5 重要
Network
Apache Software Foundation Apache DolphinScheduler Apache Software Foundation の Apache DolphinScheduler におけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2023-51770 2025-01-17 11:54 2023-12-25 Show GitHub Exploit DB Packet Storm
428 5.4 警告
Network
Brizy brizy Brizy の WordPress 用 brizy におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-1296 2025-01-17 11:54 2024-03-13 Show GitHub Exploit DB Packet Storm
429 7.5 重要
Network
BoldGrid W3 Total Cache BoldGrid の WordPress 用 W3 Total Cache における脆弱性 CWE-200
CWE-noinfo
CVE-2024-12008 2025-01-17 11:54 2024-12-1 Show GitHub Exploit DB Packet Storm
430 7.5 重要
Network
マイクロソフト Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2012
Microsoft Windows Server&…
Windows ライトウェイト ディレクトリ アクセス プロトコル (LDAP) のサービス拒否の脆弱性 CWE-476
CWE-noinfo
CVE-2024-49121 2025-01-17 10:55 2024-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 20, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
331 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Loy Yet Another Countdown allows DOM-Based XSS.This issue affects Yet Another Countdown: … CWE-79
Cross-site Scripting
CVE-2025-23891 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
332 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tom Ewer and Tito Pandu Easy Tweet Embed allows DOM-Based XSS.This issue affects Easy Tweet Embed… CWE-79
Cross-site Scripting
CVE-2025-23890 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
333 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Allan Wallick Blog Summary allows Stored XSS.This issue affects Blog Summary: from n/a thro… CWE-79
Cross-site Scripting
CVE-2025-23887 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
334 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Roberts Annie allows Stored XSS.This issue affects Annie: from n/a through 2.1.1. CWE-79
Cross-site Scripting
CVE-2025-23886 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
335 - - - Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie allows Cross Site Request Forgery.This issue affects Annie: from n/a through 2.1.1. CWE-352
 Origin Validation Error
CVE-2025-23884 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
336 - - - Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through 2.10. CWE-352
 Origin Validation Error
CVE-2025-23880 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
337 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Post-to-Post Links allows Stored XSS.This issue affects Post-to-Post Links: from n/a… CWE-79
Cross-site Scripting
CVE-2025-23878 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
338 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through… CWE-79
Cross-site Scripting
CVE-2025-23877 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
339 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jens Remus WP krpano allows Stored XSS.This issue affects WP krpano: from n/a through 1.2.1. CWE-79
Cross-site Scripting
CVE-2025-23876 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
340 - - - Cross-Site Request Forgery (CSRF) vulnerability in Tim Ridgway Better Protected Pages allows Stored XSS.This issue affects Better Protected Pages: from n/a through 1.0. CWE-352
 Origin Validation Error
CVE-2025-23875 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm