Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 12:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
581 6.1 警告
Network
Etoile Web Design Ultimate Reviews Etoile Web Design の WordPress 用 Ultimate Reviews におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-25597 2025-01-24 14:48 2024-03-15 Show GitHub Exploit DB Packet Storm
582 5.3 警告
Network
Moodle
Fedora Project
Moodle
Fedora
Moodle の Moodle 等複数ベンダの製品におけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
CWE-639
CVE-2024-25983 2025-01-24 14:47 2024-02-19 Show GitHub Exploit DB Packet Storm
583 9.8 緊急
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2024-25995 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
584 7.3 重要
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品におけるコマンドインジェクションの脆弱性 CWE-20
CWE-77
CVE-2024-25998 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
585 9.8 緊急
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における境界外書き込みに関する脆弱性 CWE-20
CWE-787
CVE-2024-26001 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
586 5.3 警告
Network
Open Knowledge Foundation CKAN Open Knowledge Foundation の CKAN におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
CWE-532
CVE-2024-27097 2025-01-24 14:47 2024-03-13 Show GitHub Exploit DB Packet Storm
587 7.8 重要
Local
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における信頼できない検索パスに関する脆弱性 CWE-426
信頼性のない検索パス
CVE-2024-28133 2025-01-24 14:47 2024-05-14 Show GitHub Exploit DB Packet Storm
588 6.1 警告
Network
Basixonline NEX-Forms Basixonline の WordPress 用 NEX-Forms におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-47389 2025-01-24 14:47 2024-10-5 Show GitHub Exploit DB Packet Storm
589 5.3 警告
Network
Nextcloud Nextcloud Server Nextcloud の Nextcloud Server における脆弱性 CWE-328
CWE-Other
CVE-2024-52521 2025-01-24 14:47 2024-11-15 Show GitHub Exploit DB Packet Storm
590 7.8 重要
Local
インテル graphics performance analyzers インテルの graphics performance analyzers における不適切なデフォルトパーミッションに関する脆弱性 CWE-276
CWE-276
CVE-2023-24460 2025-01-24 14:47 2023-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 31, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
661 4.9 MEDIUM
Network
- - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allow… - CVE-2025-21492 2025-01-25 05:15 2025-01-22 Show GitHub Exploit DB Packet Storm
662 9.8 CRITICAL
Network
scriptsbundle adforest The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to loggin… CWE-306
Missing Authentication for Critical Function
CVE-2024-12857 2025-01-25 04:18 2025-01-22 Show GitHub Exploit DB Packet Storm
663 - - - The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.8.9, in CI contexts, the IG Publisher CLI uses git commands to determine the URL of the o… CWE-200
Information Exposure
CVE-2025-24363 2025-01-25 04:15 2025-01-25 Show GitHub Exploit DB Packet Storm
664 4.3 MEDIUM
Network
- - A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this vulnerability is the function qrCode of the file sr… CWE-601
Open Redirect
CVE-2025-0705 2025-01-25 04:15 2025-01-25 Show GitHub Exploit DB Packet Storm
665 5.3 MEDIUM
Network
- - A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. Affected is the function qrCode of the file src/main/java/io/gith… CWE-404
CWE-400
 Improper Resource Shutdown or Release
 Uncontrolled Resource Consumption
CVE-2025-0704 2025-01-25 04:15 2025-01-25 Show GitHub Exploit DB Packet Storm
666 4.3 MEDIUM
Network
- - A vulnerability, which was classified as problematic, has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue affects some unknown processing of the file src/m… CWE-22
Path Traversal
CVE-2025-0703 2025-01-25 04:15 2025-01-25 Show GitHub Exploit DB Packet Storm
667 - - - The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entit… CWE-611
XXE
CVE-2024-52807 2025-01-25 04:15 2025-01-25 Show GitHub Exploit DB Packet Storm
668 - - - An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL in… - CVE-2024-55573 2025-01-25 04:15 2025-01-24 Show GitHub Exploit DB Packet Storm
669 - - - An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection … - CVE-2024-53923 2025-01-25 04:15 2025-01-24 Show GitHub Exploit DB Packet Storm
670 - - - A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP mess… - CVE-2024-24442 2025-01-25 04:15 2025-01-22 Show GitHub Exploit DB Packet Storm