Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
591 4.3 警告
Network
exclusiveaddons exclusive addons for elementor exclusiveaddons の WordPress 用 exclusive addons for elementor における脆弱性 CWE-200
CWE-noinfo
CVE-2024-10312 2025-01-27 11:06 2024-10-29 Show GitHub Exploit DB Packet Storm
592 6.1 警告
Network
icopydoc xml for google merchant center icopydoc の WordPress 用 xml for google merchant center におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-13406 2025-01-27 11:06 2025-01-22 Show GitHub Exploit DB Packet Storm
593 5.4 警告
Network
VideoWhisper.com picture gallery VideoWhisper.com の WordPress 用 picture gallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-13584 2025-01-27 11:06 2025-01-22 Show GitHub Exploit DB Packet Storm
594 2
Physics
rensas arm-trusted-firmware ルネサス エレクトロニクス株式会社の arm-trusted-firmware における整数オーバーフローの脆弱性 CWE-190
CWE-190
CVE-2024-1633 2025-01-27 11:06 2024-02-19 Show GitHub Exploit DB Packet Storm
595 5.4 警告
Network
exclusiveaddons exclusive addons for elementor exclusiveaddons の WordPress 用 exclusive addons for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2503 2025-01-27 11:06 2024-05-2 Show GitHub Exploit DB Packet Storm
596 9.8 緊急
Network
Sapplica Sentrifugo Sapplica の Sentrifugo における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29875 2025-01-27 11:06 2024-03-21 Show GitHub Exploit DB Packet Storm
597 6.1 警告
Network
Sapplica Sentrifugo Sapplica の Sentrifugo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-29878 2025-01-27 11:06 2024-03-21 Show GitHub Exploit DB Packet Storm
598 6.5 警告
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-3131 2025-01-27 11:06 2024-04-1 Show GitHub Exploit DB Packet Storm
599 5.4 警告
Network
oretnom23 computer laboratory management system oretnom23 の computer laboratory management system におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3140 2025-01-27 11:06 2024-04-1 Show GitHub Exploit DB Packet Storm
600 5.4 警告
Network
moveaddons move addons for elementor moveaddons の WordPress 用 move addons for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4695 2025-01-27 11:06 2024-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 13, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1411 5.4 MEDIUM
Network
- - The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_par… CWE-862
 Missing Authorization
CVE-2024-13775 2025-02-1 22:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1412 6.4 MEDIUM
Network
- - The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_… CWE-79
Cross-site Scripting
CVE-2024-13612 2025-02-1 22:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1413 5.4 MEDIUM
Network
- - The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including,… CWE-862
 Missing Authorization
CVE-2024-12825 2025-02-1 17:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1414 - - - An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update. - CVE-2025-23091 2025-02-1 16:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1415 6.3 MEDIUM
Network
- - The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This ma… CWE-862
 Missing Authorization
CVE-2025-0939 2025-02-1 16:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1416 6.5 MEDIUM
Network
- - The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to in… CWE-89
SQL Injection
CVE-2024-13341 2025-02-1 16:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1417 6.5 MEDIUM
Network
- - The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers… CWE-22
Path Traversal
CVE-2025-0365 2025-02-1 15:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1418 5.3 MEDIUM
Network
- - The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 vi… CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2024-12041 2025-02-1 15:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1419 8.8 HIGH
Network
- - The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible f… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2025-0366 2025-02-1 15:15 2025-02-1 Show GitHub Exploit DB Packet Storm
1420 4.3 MEDIUM
Network
- - The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all ve… CWE-862
 Missing Authorization
CVE-2024-13651 2025-02-1 13:15 2025-02-1 Show GitHub Exploit DB Packet Storm