Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
551 6.1 警告
Network
Sapplica Sentrifugo Sapplica の Sentrifugo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-29877 2025-01-27 14:38 2024-03-21 Show GitHub Exploit DB Packet Storm
552 7.2 重要
Network
aipower aipower WordPress 用 aipower における信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-0429 2025-01-27 14:38 2025-01-22 Show GitHub Exploit DB Packet Storm
553 5.5 警告
Local
F5 Networks F5OS-C
F5OS-A
F5 Networks の F5OS-A および F5OS-C におけるパストラバーサルの脆弱性 CWE-22
CWE-22
CVE-2024-23607 2025-01-27 13:46 2024-02-14 Show GitHub Exploit DB Packet Storm
554 4.9 警告
Network
F5 Networks NGINX Agent
NGINX Instance Manager
F5 Networks の NGINX Agent および NGINX Instance Manager におけるパストラバーサルの脆弱性 CWE-22
CWE-22
CVE-2024-7634 2025-01-27 13:46 2024-08-23 Show GitHub Exploit DB Packet Storm
555 - - 富士電機 Alpha5 SMART 富士電機製 ALPHA5 series Loader におけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2024-34579 2025-01-27 13:39 2025-01-17 Show GitHub Exploit DB Packet Storm
556 8.8 重要
Network
aipower aipower WordPress 用 aipower における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-13361 2025-01-27 13:34 2025-01-22 Show GitHub Exploit DB Packet Storm
557 7.5 重要
Network
Open5GS Open5GS Open5GS における到達可能なアサーションに関する脆弱性 CWE-617
CWE-617
CVE-2024-24428 2025-01-27 13:34 2024-01-25 Show GitHub Exploit DB Packet Storm
558 7.5 重要
Network
Palo Alto Networks PAN-OS Palo Alto Networks の PAN-OS における NULL ポインタデリファレンスに関する脆弱性 CWE-476
CWE-476
CVE-2024-2551 2025-01-27 13:34 2024-11-14 Show GitHub Exploit DB Packet Storm
559 6.5 警告
Network
Timothee Boussus Your Spotify Timothee Boussus の Your Spotify における脆弱性 CWE-200
CWE-noinfo
CVE-2024-28193 2025-01-27 13:34 2024-03-13 Show GitHub Exploit DB Packet Storm
560 9.8 緊急
Network
Sapplica Sentrifugo Sapplica の Sentrifugo における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29870 2025-01-27 13:34 2024-03-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 3, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
801 - - - Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload"… CWE-23
 Relative Path Traversal
CVE-2024-52012 2025-01-27 18:15 2025-01-27 Show GitHub Exploit DB Packet Storm
802 - - - Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "u… CWE-250
 Execution with Unnecessary Privileges
CVE-2025-24814 2025-01-27 18:15 2025-01-27 Show GitHub Exploit DB Packet Storm
803 - - - A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects: * O… - CVE-2025-24390 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
804 - - - Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: … - CVE-2025-24389 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
805 - - - An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X … - CVE-2024-43446 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
806 - - - A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or… - CVE-2024-43445 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
807 - - - The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded - CVE-2024-13117 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
808 - - - The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks … - CVE-2024-13116 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
809 - - - The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used aga… - CVE-2024-13094 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm
810 - - - The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add… - CVE-2024-13057 2025-01-27 15:15 2025-01-27 Show GitHub Exploit DB Packet Storm