Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
561 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21305 2025-01-27 12:32 2025-01-14 Show GitHub Exploit DB Packet Storm
562 8.1 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows リモート デスクトップ サービスのリモートでコードが実行される脆弱性 CWE-416
CWE-noinfo
CVE-2025-21297 2025-01-27 12:30 2025-01-14 Show GitHub Exploit DB Packet Storm
563 6.1 警告
Network
Rodrigue EXIF Viewer Classic EXIF Viewer Classicにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-23362 2025-01-27 12:29 2025-01-27 Show GitHub Exploit DB Packet Storm
564 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Microsoft Message Queuing (MSMQ) のサービス拒否の脆弱性 CWE-400
CWE-noinfo
CVE-2025-21290 2025-01-27 12:28 2025-01-14 Show GitHub Exploit DB Packet Storm
565 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21286 2025-01-27 12:27 2025-01-14 Show GitHub Exploit DB Packet Storm
566 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21250 2025-01-27 12:25 2025-01-14 Show GitHub Exploit DB Packet Storm
567 6.6 警告
Physics
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows デジタル メディアの特権昇格の脆弱性 CWE-125
CWE-noinfo
CVE-2025-21249 2025-01-27 12:23 2025-01-14 Show GitHub Exploit DB Packet Storm
568 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-125
CWE-noinfo
CVE-2025-21246 2025-01-27 12:22 2025-01-14 Show GitHub Exploit DB Packet Storm
569 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-190
CWE-noinfo
CVE-2025-21244 2025-01-27 12:20 2025-01-14 Show GitHub Exploit DB Packet Storm
570 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2025
Microso…
Windows テレフォニー サービスのリモートでコードが実行される脆弱性 CWE-122
CWE-noinfo
CVE-2025-21236 2025-01-27 12:18 2025-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 1, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
276221 - keep_toolkit keep_toolkit SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password. CWE-89
SQL Injection
CVE-2009-0287 2009-02-5 14:00 2009-01-28 Show GitHub Exploit DB Packet Storm
276222 - codefixer linkspro SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter. CWE-89
SQL Injection
CVE-2009-0431 2009-02-5 14:00 2009-02-5 Show GitHub Exploit DB Packet Storm
276223 - preprojects pre_classified_listings PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-6055 2009-02-5 00:30 2009-02-5 Show GitHub Exploit DB Packet Storm
276224 - google chrome Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and… NVD-CWE-Other
CVE-2009-0276 2009-02-4 14:00 2009-02-4 Show GitHub Exploit DB Packet Storm
276225 - monkey trickle Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD… NVD-CWE-Other
CVE-2009-0415 2009-02-4 14:00 2009-02-4 Show GitHub Exploit DB Packet Storm
276226 - novell groupwise Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to co… CWE-200
Information Exposure
CVE-2009-0274 2009-02-4 04:30 2009-02-4 Show GitHub Exploit DB Packet Storm
276227 - dataspade dataspade Multiple cross-site scripting (XSS) vulnerabilities in Index.asp in Dataspade 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ViewName, (2) TableName, (3) OrderBy, and (… CWE-79
Cross-site Scripting
CVE-2008-6041 2009-02-3 20:30 2009-02-3 Show GitHub Exploit DB Packet Storm
276228 - drupal internationalization Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restr… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-0382 2009-02-3 04:30 2009-02-3 Show GitHub Exploit DB Packet Storm
276229 - hp hplip hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP in… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-0122 2009-01-31 15:54 2009-01-16 Show GitHub Exploit DB Packet Storm
276230 - apple cups The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy a… CWE-255
Credentials Management
CVE-2008-5184 2009-01-29 15:58 2008-11-21 Show GitHub Exploit DB Packet Storm