Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 17, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
521 7.5 重要
Network
IBM IBM Maximo Application Suite IBM の IBM Maximo Application Suite におけるパストラバーサルの脆弱性 New CWE-22
パス・トラバーサル
CVE-2024-22328 2025-01-15 12:10 2024-04-5 Show GitHub Exploit DB Packet Storm
522 7.8 重要
Local
IBM IBM Security Guardium IBM の IBM Security Guardium における重要なリソースに対する不適切なパーミッションの割り当てに関する脆弱性 New CWE-732
重要なリソースに対する不適切なパーミッションの割り当て
CVE-2023-47712 2025-01-15 12:10 2023-11-9 Show GitHub Exploit DB Packet Storm
523 6.5 警告
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2012
Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microso…
Windows 分散ファイル システムの情報漏えいの脆弱性 New CWE-125
CWE-noinfo
CVE-2024-26226 2025-01-15 12:03 2024-04-9 Show GitHub Exploit DB Packet Storm
524 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2012
Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microso…
DHCP Server サービスのサービス拒否の脆弱性 New CWE-400
CWE-noinfo
CVE-2024-26212 2025-01-15 12:00 2024-04-9 Show GitHub Exploit DB Packet Storm
525 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2012
Microsoft Window…
Windows ルーティングとリモート アクセス サービス (RRAS) のリモートでコードが実行される脆弱性 New CWE-122
CWE-noinfo
CVE-2024-26205 2025-01-15 11:50 2024-04-9 Show GitHub Exploit DB Packet Storm
526 5.4 警告
Network
IBM IBM Aspera Faspex IBM の IBM Aspera Faspex におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2023-37411 2025-01-15 11:45 2023-07-5 Show GitHub Exploit DB Packet Storm
527 7.5 重要
Network
IBM IBM TXSeries for Multiplatforms IBM の IBM TXSeries for Multiplatforms における認証情報の不十分な保護に関する脆弱性 New CWE-522
認証情報の不十分な保護
CVE-2024-22345 2025-01-15 11:45 2024-05-9 Show GitHub Exploit DB Packet Storm
528 8 重要
Adjacent
マイクロソフト Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2012
Microsoft Windows 11
Microsoft Windows Server&…
セキュア ブートのセキュリティ機能のバイパスの脆弱性 New CWE-20
CWE-noinfo
CVE-2024-26189 2025-01-15 11:44 2024-04-9 Show GitHub Exploit DB Packet Storm
529 7.8 重要
Local
マイクロソフト Microsoft Windows 11
Microsoft Windows 10
Microsoft Windows Server 2022
Windows 認証の特権の昇格の脆弱性 New CWE-59
CWE-noinfo
CVE-2024-21447 2025-01-15 11:39 2024-04-9 Show GitHub Exploit DB Packet Storm
530 6.5 警告
Network
マイクロソフト Azure Compute Gallery Azure Compute Gallery の特権の昇格の脆弱性 New CWE-284
CWE-noinfo
CVE-2024-21424 2025-01-15 11:39 2024-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 18, 2025, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
141 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jens Remus WP krpano allows Stored XSS.This issue affects WP krpano: from n/a through 1.2.1. New CWE-79
Cross-site Scripting
CVE-2025-23876 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
142 - - - Cross-Site Request Forgery (CSRF) vulnerability in Tim Ridgway Better Protected Pages allows Stored XSS.This issue affects Better Protected Pages: from n/a through 1.0. New CWE-352
 Origin Validation Error
CVE-2025-23875 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
143 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anshi Solutions Category D3 Tree allows Stored XSS.This issue affects Category D3 Tree: from n/a … New CWE-79
Cross-site Scripting
CVE-2025-23873 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
144 - - - Cross-Site Request Forgery (CSRF) vulnerability in PayForm PayForm allows Stored XSS.This issue affects PayForm: from n/a through 2.0. New CWE-352
 Origin Validation Error
CVE-2025-23872 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
145 - - - Cross-Site Request Forgery (CSRF) vulnerability in Bas Matthee LSD Google Maps Embedder allows Cross Site Request Forgery.This issue affects LSD Google Maps Embedder: from n/a through 1.1. New CWE-352
 Origin Validation Error
CVE-2025-23871 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
146 - - - Cross-Site Request Forgery (CSRF) vulnerability in Robert Nicholson Copyright Safeguard Footer Notice allows Stored XSS.This issue affects Copyright Safeguard Footer Notice: from n/a through 3.0. New CWE-352
 Origin Validation Error
CVE-2025-23870 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
147 - - - Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.k.a CyberJack CJ Custom Content allows Stored XSS.This issue affects CJ Custom Content: from n/a through 2.0. New CWE-352
 Origin Validation Error
CVE-2025-23869 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
148 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markus Liebelt Chess Tempo Viewer allows Stored XSS.This issue affects Chess Tempo Viewer: from n… New CWE-79
Cross-site Scripting
CVE-2025-23868 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
149 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pressfore Winning Portfolio allows Stored XSS.This issue affects Winning Portfolio: from n/a thro… New CWE-79
Cross-site Scripting
CVE-2025-23865 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
150 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Code Snippets (Luke America) WCS QR Code Generator allows Stored XSS.This issue affects WCS QR… New CWE-79
Cross-site Scripting
CVE-2025-23864 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm