Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
501 5.9 警告
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows Kerberos の情報漏えいの脆弱性 CWE-200
CWE-noinfo
CVE-2025-21242 2025-01-27 17:18 2025-01-14 Show GitHub Exploit DB Packet Storm
502 6.5 警告
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows 10
Microsoft Windows Server&…
Windows Geolocation Service の情報漏えいの脆弱性 CWE-284
CWE-noinfo
CVE-2025-21301 2025-01-27 17:18 2025-01-14 Show GitHub Exploit DB Packet Storm
503 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21240 2025-01-27 17:16 2025-01-14 Show GitHub Exploit DB Packet Storm
504 6.5 警告
Local
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows COM サーバーの情報漏えいの脆弱性 CWE-908
CWE-noinfo
CVE-2025-21288 2025-01-27 17:14 2025-01-14 Show GitHub Exploit DB Packet Storm
505 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows 10
Microsoft Windows Server&…
Windows Kerberos のセキュリティ機能のバイパスの脆弱性 CWE-922
CWE-noinfo
CVE-2025-21299 2025-01-27 17:06 2025-01-14 Show GitHub Exploit DB Packet Storm
506 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21237 2025-01-27 17:04 2025-01-14 Show GitHub Exploit DB Packet Storm
507 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Microsoft ダイジェスト認証のリモートでコードが実行される脆弱性 CWE-591
CWE-noinfo
CVE-2025-21294 2025-01-27 17:00 2025-01-14 Show GitHub Exploit DB Packet Storm
508 9.8 緊急
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows Reliable Multicast Transport Driver (RMCAST) のリモートでコードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21307 2025-01-27 16:53 2025-01-14 Show GitHub Exploit DB Packet Storm
509 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21303 2025-01-27 16:48 2025-01-14 Show GitHub Exploit DB Packet Storm
510 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2016
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Window…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21252 2025-01-27 16:46 2025-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 19, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1451 - - - 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. - CVE-2024-47258 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1452 - - - Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used for decryption of certain data wi… - CVE-2024-47256 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1453 - - - Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working state. - CVE-2024-13417 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1454 - - - WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database connection strings, which allows an attacker to read local file… - CVE-2025-24787 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1455 - - - WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an … - CVE-2025-24786 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1456 - - - Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authen… - CVE-2024-57523 2025-02-7 05:15 2025-02-7 Show GitHub Exploit DB Packet Storm
1457 - - - SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied paramete… - CVE-2025-25064 2025-02-7 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1458 - - - Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuth… - CVE-2025-24860 2025-02-7 05:15 2025-02-4 Show GitHub Exploit DB Packet Storm
1459 4.3 MEDIUM
Network
mozilla firefox
thunderbird
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2025-1019 2025-02-7 04:40 2025-02-4 Show GitHub Exploit DB Packet Storm
1460 5.3 MEDIUM
Network
mozilla firefox
thunderbird
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affect… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2025-1018 2025-02-7 04:40 2025-02-4 Show GitHub Exploit DB Packet Storm