You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
|
Update Date":Jan. 21, 2025, 12:02 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
441 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2008 Microsoft Windows Server 2022 Microsoft Windows 11 Microsoft Windows Server 2019 Microsoft Window… |
Windows Win32 カーネル サブシステムの特権の昇格の脆弱性 |
CWE-416 CWE-noinfo |
CVE-2024-30049 | 2025-01-17 15:30 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
442 | 9.8 |
緊急
Network Hitachi Energy |
FOXMAN-UN |
UNEM
Hitachi Energy の FOXMAN-UN および UNEM における脆弱性
|
CWE-noinfo
|
情報不足
CVE-2024-2012
|
2025-01-17 15:25 |
2024-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
443 | 10 |
緊急
Network Hitachi Energy |
FOXMAN-UN |
UNEM
Hitachi Energy の FOXMAN-UN および UNEM における重要な機能に対する認証の欠如に関する脆弱性
|
CWE-306
|
重要な機能に対する認証の欠如 解説
CVE-2024-2013
|
2025-01-17 15:22 |
2024-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
444 | 7.5 |
重要
Network マイクロソフト |
Microsoft SharePoint Server |
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server の情報漏えいの脆弱性
|
CWE-611 |
CWE-noinfo
CVE-2024-30043
|
2025-01-17 15:21 |
2024-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
445 | 5.5 |
警告
Local |
マイクロソフト |
Microsoft Windows Server 2008 Microsoft Windows Server 2022 Microsoft Windows 11 Microsoft Windows Server 2019 Microsoft Window… |
Windows 共通ログ ファイル システム ドライバーの特権の昇格の脆弱性 |
CWE-125 CWE-noinfo |
CVE-2024-30037 | 2025-01-17 15:20 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
446 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2022 Microsoft Windows 11 Microsoft Windows Server 2019 Microsoft Windows Server 2016 Microsoft Window… |
Windows DWM Core ライブラリの特権の昇格の脆弱性 |
CWE-416 CWE-noinfo |
CVE-2024-30032 | 2025-01-17 15:08 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
447 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2008 Microsoft Windows Server 2022 Microsoft Windows 11 Microsoft Windows Server 2019 Microsoft Window… |
Win32k の特権の昇格の脆弱性 |
CWE-416 CWE-noinfo |
CVE-2024-30028 | 2025-01-17 15:02 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
448 | 7.8 |
重要
Local |
Progress Software Corporation | telerik reporting | Progress Software Corporation の telerik reporting における信頼できないデータのデシリアライゼーションに関する脆弱性 |
CWE-502 CWE-502 |
CVE-2024-1801 | 2025-01-17 15:01 | 2024-03-20 | Show | GitHub Exploit DB Packet Storm |
449 | 5.9 |
警告
Network |
Devolutions | Devolutions Remote Desktop Manager | Devolutions の Devolutions Remote Desktop Manager における不完全なクリーンアップに関する脆弱性 |
CWE-459
不完全なクリーンアップ |
CVE-2024-2403 | 2025-01-17 15:01 | 2024-03-13 | Show | GitHub Exploit DB Packet Storm |
450 | 5.4 |
警告
Network |
Wpmet | ElementsKit Elementor addons | Wpmet の WordPress 用 ElementsKit Elementor addons におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2024-3650 | 2025-01-17 15:01 | 2024-05-2 | Show | GitHub Exploit DB Packet Storm |
Update Date:Jan. 21, 2025, 4:11 a.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
441 | 8.8 |
HIGH
Network |
chrome | Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CWE-125
Out-of-bounds Read |
CVE-2025-0437 | 2025-01-17 05:35 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm | |
442 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2022_23h2 windows_11_23h2 windows_10_1607 windows_10_1809 windows_10_1507 windows_10_21h2 windows_10_22h2 windows_11_… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21417 | 2025-01-17 05:34 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
443 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21413 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
444 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21411 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
445 | 8.8 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Telephony Service Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2025-21409 | 2025-01-17 05:33 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
446 | - | - | - | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carrotbits Greek Namedays Widget From Eortologio.Net allows Stored XSS.This issue affects Greek N… |
CWE-79
Cross-site Scripting |
CVE-2025-23783 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
447 | - | - | - | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revolutionart Marmoset Viewer allows Stored XSS.This issue affects Marmoset Viewer: from n/a thro… |
CWE-79
Cross-site Scripting |
CVE-2025-23767 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
448 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Mahdi Khaksar mybb Last Topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through 1.0. |
CWE-352
Origin Validation Error |
CVE-2025-23749 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
449 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor internet & marketing Call me Now allows Stored XSS.This issue affects Call me Now: from n/a through 1.0.5. |
CWE-352
Origin Validation Error |
CVE-2025-23745 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm | |
450 | - | - | - | Cross-Site Request Forgery (CSRF) vulnerability in Martijn Scheybeler Social Analytics allows Stored XSS.This issue affects Social Analytics: from n/a through 0.2. |
CWE-352
Origin Validation Error |
CVE-2025-23743 | 2025-01-17 05:15 | 2025-01-17 | Show | GitHub Exploit DB Packet Storm |