Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 27, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
61 8.8 重要
Network
Stranger Studios Paid Memberships Pro Stranger Studios の WordPress 用 Paid Memberships Pro における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2023-39990 2025-01-27 14:39 2023-08-8 Show GitHub Exploit DB Packet Storm
62 7.5 重要
Network
Palo Alto Networks PAN-OS Palo Alto Networks の PAN-OS における NULL ポインタデリファレンスに関する脆弱性 New CWE-476
CWE-476
CVE-2024-2550 2025-01-27 14:39 2024-11-14 Show GitHub Exploit DB Packet Storm
63 7.5 重要
Network
lfprojects mlflow lfprojects の mlflow におけるパストラバーサルの脆弱性 New CWE-22
CWE-29
CVE-2024-3848 2025-01-27 14:38 2024-05-16 Show GitHub Exploit DB Packet Storm
64 9.8 緊急
Network
Themeum Tutor LMS Themeum の WordPress 用 Tutor LMS における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-4223 2025-01-27 14:38 2024-05-16 Show GitHub Exploit DB Packet Storm
65 5.4 警告
Network
getshortcodes shortcodes ultimate getshortcodes の WordPress 用 shortcodes ultimate におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4553 2025-01-27 14:38 2024-05-21 Show GitHub Exploit DB Packet Storm
66 5.4 警告
Network
Elementor Elementor Website Builder Elementor の WordPress 用 Elementor Website Builder におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4619 2025-01-27 14:38 2024-05-21 Show GitHub Exploit DB Packet Storm
67 5.4 警告
Network
HasThemes HT Mega - Absolute Addons For Elementor HasThemes の WordPress 用 HT Mega - Absolute Addons For Elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4876 2025-01-27 14:38 2024-05-21 Show GitHub Exploit DB Packet Storm
68 7.3 重要
Network
GamiPress GamiPress - Vimeo integration GamiPress の WordPress 用 GamiPress - Vimeo integration におけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2024-13495 2025-01-27 14:38 2025-01-22 Show GitHub Exploit DB Packet Storm
69 7.3 重要
Network
GamiPress GamiPress - Vimeo integration GamiPress の WordPress 用 GamiPress - Vimeo integration におけるコードインジェクションの脆弱性 New CWE-94
コード・インジェクション
CVE-2024-13499 2025-01-27 14:38 2025-01-22 Show GitHub Exploit DB Packet Storm
70 6.4 警告
Network
Apache Software Foundation Apache Pulsar Apache Software Foundation の Apache Pulsar における不正な認証に関する脆弱性 New CWE-863
不正な認証
CVE-2024-29834 2025-01-27 14:38 2024-04-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 27, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
731 - - - A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2022-23439 2025-01-22 19:15 2025-01-22 Show GitHub Exploit DB Packet Storm
732 - - - Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected produc… CWE-78
OS Command 
CVE-2025-23237 2025-01-22 15:15 2025-01-22 Show GitHub Exploit DB Packet Storm
733 - - - Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, and open specifi… CWE-1242
 Inclusion of Undocumented Features or Chicken Bits
CVE-2025-22450 2025-01-22 15:15 2025-01-22 Show GitHub Exploit DB Packet Storm
734 - - - Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If this vulnerability is exploited, an arbitrar… CWE-78
OS Command 
CVE-2025-20617 2025-01-22 15:15 2025-01-22 Show GitHub Exploit DB Packet Storm
735 8.6 HIGH
Local
- - A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might miti… CWE-269
 Improper Privilege Management
CVE-2024-11218 2025-01-22 14:15 2025-01-22 Show GitHub Exploit DB Packet Storm
736 - - - With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an inst… - CVE-2025-23090 2025-01-22 11:15 2025-01-22 Show GitHub Exploit DB Packet Storm
737 - - - With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an insta… - CVE-2025-23083 2025-01-22 11:15 2025-01-22 Show GitHub Exploit DB Packet Storm
738 3.1 LOW
Network
- - A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads t… CWE-99
Resource Injection
CVE-2025-0625 2025-01-22 11:15 2025-01-22 Show GitHub Exploit DB Packet Storm
739 - - - SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. CWE-20
 Improper Input Validation 
CVE-2024-45479 2025-01-22 07:15 2025-01-22 Show GitHub Exploit DB Packet Storm
740 - - - Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP c… - CVE-2024-24444 2025-01-22 07:15 2025-01-22 Show GitHub Exploit DB Packet Storm