Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 6, 2024, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
41 7.8 重要
Local
シーメンス Simcenter Femap シーメンスの Simcenter Femap における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-24924 2024-10-4 14:22 2024-02-13 Show GitHub Exploit DB Packet Storm
42 8 重要
Adjacent
Ivanti Ivanti Endpoint Manager Ivanti の Ivanti Endpoint Manager における SQL インジェクションの脆弱性 New CWE-89
CWE-89
CVE-2024-29829 2024-10-4 14:18 2024-05-31 Show GitHub Exploit DB Packet Storm
43 7.8 重要
Local
富士電機 Tellus Lite V-Simulator 富士電機の Tellus Lite V-Simulator における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-37022 2024-10-4 14:18 2024-06-13 Show GitHub Exploit DB Packet Storm
44 4.3 警告
Network
Elasticsearch B.V. Kibana Elasticsearch B.V. の Kibana における脆弱性 New CWE-Other
その他
CVE-2024-37279 2024-10-4 14:18 2024-06-13 Show GitHub Exploit DB Packet Storm
45 8.8 重要
Network
woodpecker-ci woodpecker woodpecker-ci の woodpecker における脆弱性 New CWE-74
CWE-noinfo
CVE-2024-41121 2024-10-4 14:18 2024-07-19 Show GitHub Exploit DB Packet Storm
46 4.6 警告
Network
Liferay Digital Experience Platform
Liferay Portal
Liferay の Digital Experience Platform および Liferay Portal におけるセッションの固定化の脆弱性 New CWE-384
CWE-384
CVE-2023-47798 2024-10-4 14:15 2023-11-10 Show GitHub Exploit DB Packet Storm
47 9.8 緊急
Network
nationalkeep cybermath nationalkeep の cybermath における不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2024-7108 2024-10-4 14:15 2024-09-26 Show GitHub Exploit DB Packet Storm
48 5.5 警告
Local
PaperCut Software International Pty PaperCut NG
PaperCut MF
PaperCut Software International Pty の PaperCut MF および PaperCut NG におけるコマンドインジェクションの脆弱性 New CWE-77
CWE-77
CVE-2024-8405 2024-10-4 14:15 2024-09-26 Show GitHub Exploit DB Packet Storm
49 6.1 警告
Network
WPFACTORY eu/uk vat manager for woocommerce WPFACTORY の WordPress 用 eu/uk vat manager for woocommerce におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-8788 2024-10-4 14:15 2024-09-28 Show GitHub Exploit DB Packet Storm
50 5.4 警告
Network
JetBrains Toolbox themedy の WordPress 用 toolbox におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-9177 2024-10-4 14:15 2024-09-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Oct. 6, 2024, 8:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
81 6.4 MEDIUM
Network
- - The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitiz… New CWE-79
Cross-site Scripting
CVE-2024-9455 2024-10-5 11:15 2024-10-5 Show GitHub Exploit DB Packet Storm
82 - - - The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, … New CWE-79
Cross-site Scripting
CVE-2024-9385 2024-10-5 11:15 2024-10-5 Show GitHub Exploit DB Packet Storm
83 - - - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki -… New - CVE-2024-47841 2024-10-5 11:15 2024-10-5 Show GitHub Exploit DB Packet Storm
84 5.4 MEDIUM
Network
websevendev attributes_for_blocks The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 due to insufficient inp… Update CWE-79
Cross-site Scripting
CVE-2024-8318 2024-10-5 11:10 2024-09-4 Show GitHub Exploit DB Packet Storm
85 8.8 HIGH
Network
mainwp updraftplus_extension Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6. Update CWE-862
 Missing Authorization
CVE-2023-23640 2024-10-5 11:04 2024-06-9 Show GitHub Exploit DB Packet Storm
86 8.8 HIGH
Network
androidbubble wp_sort_order Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1. Update CWE-862
 Missing Authorization
CVE-2024-31294 2024-10-5 11:01 2024-06-9 Show GitHub Exploit DB Packet Storm
87 8.8 HIGH
Network
wpxpo postx Missing Authorization vulnerability in Post Grid Team by WPXPO PostX – Gutenberg Blocks for Post Grid.This issue affects PostX – Gutenberg Blocks for Post Grid: from n/a through 3.2.3. Update CWE-862
 Missing Authorization
CVE-2024-31246 2024-10-5 10:59 2024-06-9 Show GitHub Exploit DB Packet Storm
88 9.8 CRITICAL
Network
mrebabi new_order_notification_for_woocommerce Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: from n/a through 2.0.2. Update CWE-862
 Missing Authorization
CVE-2024-31098 2024-10-5 10:54 2024-06-9 Show GitHub Exploit DB Packet Storm
89 9.8 CRITICAL
Network
rems school_task_manager Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. Update CWE-89
SQL Injection
CVE-2024-24142 2024-10-5 10:43 2024-02-14 Show GitHub Exploit DB Packet Storm
90 9.8 CRITICAL
Network
mainwp staging_extension Missing Authorization vulnerability in MainWP MainWP Staging Extension.This issue affects MainWP Staging Extension: from n/a through 4.0.3. Update CWE-862
 Missing Authorization
CVE-2023-23639 2024-10-5 10:37 2024-06-9 Show GitHub Exploit DB Packet Storm