Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
641 5.5 警告
Local
Linux Linux Kernel Linux の Linux Kernel における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2024-57938 2025-01-24 15:08 2024-12-23 Show GitHub Exploit DB Packet Storm
642 4.9 警告
Network
openautomationsoftware oas platform openautomationsoftware の oas platform における脆弱性 CWE-73
CWE-Other
CVE-2024-22178 2025-01-24 14:55 2024-04-3 Show GitHub Exploit DB Packet Storm
643 6.5 警告
Network
Fortra GoAnywhere Managed File Transfer Fortra の GoAnywhere Managed File Transfer におけるパストラバーサルの脆弱性 CWE-22
CWE-22
CVE-2024-25156 2025-01-24 14:48 2024-03-14 Show GitHub Exploit DB Packet Storm
644 6.1 警告
Network
Etoile Web Design Ultimate Reviews Etoile Web Design の WordPress 用 Ultimate Reviews におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-25597 2025-01-24 14:48 2024-03-15 Show GitHub Exploit DB Packet Storm
645 5.3 警告
Network
Moodle
Fedora Project
Moodle
Fedora
Moodle の Moodle 等複数ベンダの製品におけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
CWE-639
CVE-2024-25983 2025-01-24 14:47 2024-02-19 Show GitHub Exploit DB Packet Storm
646 9.8 緊急
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2024-25995 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
647 7.3 重要
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品におけるコマンドインジェクションの脆弱性 CWE-20
CWE-77
CVE-2024-25998 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
648 9.8 緊急
Network
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における境界外書き込みに関する脆弱性 CWE-20
CWE-787
CVE-2024-26001 2025-01-24 14:47 2024-03-12 Show GitHub Exploit DB Packet Storm
649 5.3 警告
Network
Open Knowledge Foundation CKAN Open Knowledge Foundation の CKAN におけるログファイルからの情報漏えいに関する脆弱性 CWE-532
CWE-532
CVE-2024-27097 2025-01-24 14:47 2024-03-13 Show GitHub Exploit DB Packet Storm
650 7.8 重要
Local
PHOENIX CONTACT charx sec-3000 ファームウェア
charx sec-3150 ファームウェア
charx sec-3050 ファームウェア
charx sec-3100 ファームウェア
複数の PHOENIX CONTACT 製品における信頼できない検索パスに関する脆弱性 CWE-426
信頼性のない検索パス
CVE-2024-28133 2025-01-24 14:47 2024-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 2, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
811 4.8 MEDIUM
Network
- - IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get … CWE-614
 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2024-28770 2025-01-27 11:15 2025-01-27 Show GitHub Exploit DB Packet Storm
812 2.4 LOW
Adjacent
- - IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the… CWE-548
 Exposure of Information Through Directory Listing
CVE-2024-28766 2025-01-27 11:15 2025-01-27 Show GitHub Exploit DB Packet Storm
813 5.4 MEDIUM
Network
- - IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… CWE-79
Cross-site Scripting
CVE-2023-46187 2025-01-27 11:15 2025-01-27 Show GitHub Exploit DB Packet Storm
814 4.7 MEDIUM
Network
- - A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manip… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-0722 2025-01-27 09:15 2025-01-27 Show GitHub Exploit DB Packet Storm
815 4.3 MEDIUM
Network
- - A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument username leads… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-0721 2025-01-27 09:15 2025-01-27 Show GitHub Exploit DB Packet Storm
816 3.3 LOW
Local
- - A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rt… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2025-0720 2025-01-27 08:15 2025-01-27 Show GitHub Exploit DB Packet Storm
817 6.5 MEDIUM
Network
- - IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism. CWE-863
 Incorrect Authorization
CVE-2023-50946 2025-01-27 01:15 2025-01-27 Show GitHub Exploit DB Packet Storm
818 6.2 MEDIUM
Local
- - IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. CWE-256
Plaintext Storage of a Password 
CVE-2023-50945 2025-01-27 01:15 2025-01-27 Show GitHub Exploit DB Packet Storm
819 4.2 MEDIUM
Physics
- - IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning. CWE-295
Improper Certificate Validation 
CVE-2023-38009 2025-01-27 01:15 2025-01-27 Show GitHub Exploit DB Packet Storm
820 6.2 MEDIUM
Local
- - IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system. CWE-525
 Use of Web Browser Cache Containing Sensitive Information
CVE-2024-31906 2025-01-27 00:15 2025-01-27 Show GitHub Exploit DB Packet Storm