Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
741 8.2 重要
Network
Nextcloud Nextcloud Server Nextcloud の Nextcloud Server における重要な情報のセキュアでない格納に関する脆弱性 CWE-922
重要な情報のセキュアでない格納
CVE-2024-52519 2025-01-24 11:31 2024-11-15 Show GitHub Exploit DB Packet Storm
742 5.5 警告
Local
IObit Protected Folder IObit の Protected Folder における NULL ポインタデリファレンスに関する脆弱性 CWE-404
CWE-476
CWE-476
CVE-2025-0221 2025-01-24 11:31 2025-01-5 Show GitHub Exploit DB Packet Storm
743 5.4 警告
Network
Leap13 premium addons Leap13 の WordPress 用 premium addons におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2239 2025-01-24 11:19 2024-03-13 Show GitHub Exploit DB Packet Storm
744 5.4 警告
Network
bobbingwide oik bobbingwide の WordPress 用 oik におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2256 2025-01-24 11:19 2024-03-14 Show GitHub Exploit DB Packet Storm
745 5.4 警告
Network
Leap13 Premium Addons for Elementor Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2399 2025-01-24 11:19 2024-03-15 Show GitHub Exploit DB Packet Storm
746 4.8 警告
Network
doofinder doofinder WordPress 用 doofinder におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-25596 2025-01-24 11:19 2024-03-15 Show GitHub Exploit DB Packet Storm
747 8.8 重要
Network
Moodle
Fedora Project
Moodle
Fedora
Moodle の Moodle 等複数ベンダの製品におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
CWE-352
CVE-2024-25982 2025-01-24 11:19 2024-02-19 Show GitHub Exploit DB Packet Storm
748 5.3 警告
Network
PHOENIX CONTACT charx sec-3150 ファームウェア
charx sec-3100 ファームウェア
charx sec-3000 ファームウェア
charx sec-3050 ファームウェア
複数の PHOENIX CONTACT 製品における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2024-25997 2025-01-24 11:19 2024-03-12 Show GitHub Exploit DB Packet Storm
749 7.5 重要
Network
PHOENIX CONTACT charx sec-3150 ファームウェア
charx sec-3100 ファームウェア
charx sec-3000 ファームウェア
charx sec-3050 ファームウェア
複数の PHOENIX CONTACT 製品における境界外読み取りに関する脆弱性 CWE-125
CWE-20
CVE-2024-26000 2025-01-24 11:19 2024-03-12 Show GitHub Exploit DB Packet Storm
750 4.9 警告
Network
openautomationsoftware oas platform openautomationsoftware の oas platform における入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2024-27201 2025-01-24 11:19 2024-04-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 25, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274091 - nukebookmarks nukebookmarks marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message. NVD-CWE-Other
CVE-2005-0900 2016-10-18 12:15 2005-03-26 Show GitHub Exploit DB Packet Storm
274092 - nukebookmarks nukebookmarks Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or … NVD-CWE-Other
CVE-2005-0901 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274093 - nukebookmarks nukebookmarks SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter. NVD-CWE-Other
CVE-2005-0902 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274094 - apple quicktime_pictureviewer Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data. NVD-CWE-Other
CVE-2005-0903 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274095 - maxthon maxthon Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property. NVD-CWE-Other
CVE-2005-0905 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274096 - tkais_shoutbox tkais_shoutbox PHP remote file inclusion vulnerability in shoutact.php for TKai's Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter. NVD-CWE-Other
CVE-2005-0909 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274097 - - - Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NVD-CWE-Other
CVE-2005-0925 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274098 - photopost photopost_php_pro Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) … NVD-CWE-Other
CVE-2005-0928 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274099 - - - SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.p… NVD-CWE-Other
CVE-2005-0929 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm
274100 - esmi paypal_storefront Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to produc… NVD-CWE-Other
CVE-2005-0935 2016-10-18 12:15 2005-05-2 Show GitHub Exploit DB Packet Storm