Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 18, 2025, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
461 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 New CWE-352
同一生成元ポリシー違反
CVE-2024-4590 2025-01-16 11:32 2024-05-7 Show GitHub Exploit DB Packet Storm
462 7.5 重要
Network
Squid-cache.org
NetApp
bluexp
Squid
Squid-cache.org の Squid 等複数ベンダの製品における脆弱性 New CWE-182
CWE-400
CWE-Other
CVE-2024-25617 2025-01-16 11:31 2024-02-14 Show GitHub Exploit DB Packet Storm
463 6.5 警告
Network
デル EMC PowerScale OneFS デルの EMC PowerScale OneFS における脆弱性 New CWE-687
CWE-Other
CVE-2024-49603 2025-01-16 11:31 2024-12-9 Show GitHub Exploit DB Packet Storm
464 7.8 重要
Local
クアルコム fastconnect 6700 ファームウェア
fastconnect 6800 ファームウェア
AR8035 ファームウェア
qamsrv1h ファームウェア
fastconnect 6200 ファームウェア
qamsrv1m ファームウェア
QCA6420 …
複数のクアルコム製品における整数オーバーフローの脆弱性 New CWE-190
CWE-190
CVE-2023-43530 2025-01-16 11:26 2023-09-19 Show GitHub Exploit DB Packet Storm
465 4.3 警告
Network
Themeum Tutor LMS Themeum の WordPress 用 Tutor LMS における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-1133 2025-01-16 11:26 2024-02-29 Show GitHub Exploit DB Packet Storm
466 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-4119 2025-01-16 11:26 2024-04-24 Show GitHub Exploit DB Packet Storm
467 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4376 2025-01-16 11:26 2024-05-31 Show GitHub Exploit DB Packet Storm
468 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-6495 2025-01-16 11:26 2024-07-12 Show GitHub Exploit DB Packet Storm
469 7.8 重要
Local
クアルコム qfw7124 ファームウェア
AR8035 ファームウェア
qamsrv1h ファームウェア
SA6145P ファームウェア
qcn6274 ファームウェア
qcn6224 ファームウェア
qamsrv1m ファームウェア
QCA6584AU ファームウェア
QCA8…
複数のクアルコム製品における古典的バッファオーバーフローの脆弱性 New CWE-120
CWE-120
CVE-2023-43525 2025-01-16 11:16 2023-09-19 Show GitHub Exploit DB Packet Storm
470 4.3 警告
Network
Basixonline NEX-Forms Basixonline の WordPress 用 NEX-Forms における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-0907 2025-01-16 11:16 2024-02-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221 4.3 MEDIUM
Network
apple ipados
iphone_os
watchos
visionos
A path handling issue was addressed with improved logic. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An attacker with access to calendar data could also read reminder… New CWE-22
Path Traversal
CVE-2024-54535 2025-01-17 05:36 2025-01-16 Show GitHub Exploit DB Packet Storm
222 8.8 HIGH
Network
google chrome Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) New CWE-125
Out-of-bounds Read
CVE-2025-0437 2025-01-17 05:35 2025-01-15 Show GitHub Exploit DB Packet Storm
223 8.8 HIGH
Network
microsoft windows_server_2008
windows_server_2012
windows_server_2022_23h2
windows_11_23h2
windows_10_1607
windows_10_1809
windows_10_1507
windows_10_21h2
windows_10_22h2
windows_11_…
Windows Telephony Service Remote Code Execution Vulnerability New NVD-CWE-noinfo
CVE-2025-21417 2025-01-17 05:34 2025-01-15 Show GitHub Exploit DB Packet Storm
224 8.8 HIGH
Network
microsoft windows_server_2008
windows_server_2012
windows_server_2025
windows_server_2022_23h2
windows_10_1507
windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows…
Windows Telephony Service Remote Code Execution Vulnerability New NVD-CWE-noinfo
CVE-2025-21413 2025-01-17 05:33 2025-01-15 Show GitHub Exploit DB Packet Storm
225 8.8 HIGH
Network
microsoft windows_server_2008
windows_server_2012
windows_server_2025
windows_server_2022_23h2
windows_10_1507
windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows…
Windows Telephony Service Remote Code Execution Vulnerability New NVD-CWE-noinfo
CVE-2025-21411 2025-01-17 05:33 2025-01-15 Show GitHub Exploit DB Packet Storm
226 8.8 HIGH
Network
microsoft windows_server_2008
windows_server_2012
windows_server_2025
windows_server_2022_23h2
windows_10_1507
windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows…
Windows Telephony Service Remote Code Execution Vulnerability New NVD-CWE-noinfo
CVE-2025-21409 2025-01-17 05:33 2025-01-15 Show GitHub Exploit DB Packet Storm
227 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carrotbits Greek Namedays Widget From Eortologio.Net allows Stored XSS.This issue affects Greek N… New CWE-79
Cross-site Scripting
CVE-2025-23783 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
228 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revolutionart Marmoset Viewer allows Stored XSS.This issue affects Marmoset Viewer: from n/a thro… New CWE-79
Cross-site Scripting
CVE-2025-23767 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
229 - - - Cross-Site Request Forgery (CSRF) vulnerability in Mahdi Khaksar mybb Last Topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through 1.0. New CWE-352
 Origin Validation Error
CVE-2025-23749 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm
230 - - - Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor internet & marketing Call me Now allows Stored XSS.This issue affects Call me Now: from n/a through 1.0.5. New CWE-352
 Origin Validation Error
CVE-2025-23745 2025-01-17 05:15 2025-01-17 Show GitHub Exploit DB Packet Storm