Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 24, 2025, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
771 4.8 警告
Network
shopfiles ebook store shopfiles の WordPress 用 ebook store におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-23501 2025-01-17 19:40 2024-02-29 Show GitHub Exploit DB Packet Storm
772 6.5 警告
Network
axiosys bento4 axiosys の bento4 における有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
CWE-401
CVE-2024-24155 2025-01-17 19:40 2024-02-29 Show GitHub Exploit DB Packet Storm
773 5.4 警告
Network
Vanderbilt redcap Vanderbilt の redcap におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-79
CVE-2024-56377 2025-01-17 19:40 2024-12-22 Show GitHub Exploit DB Packet Storm
774 7.5 重要
Network
SimpleHelp Ltd SimpleHelp SimpleHelp Ltd の SimpleHelp におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2024-57727 2025-01-17 19:40 2025-01-15 Show GitHub Exploit DB Packet Storm
775 5.4 警告
Network
Themeisle Orbit Fox ThemeIsle の WordPress 用 Orbit Fox におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-0311 2025-01-17 19:40 2025-01-10 Show GitHub Exploit DB Packet Storm
776 6.2 警告
Local
FreeType Project FreeType FreeType Project の FreeType における整数オーバーフローの脆弱性 CWE-190
CWE-190
CVE-2025-23022 2025-01-17 19:40 2025-01-10 Show GitHub Exploit DB Packet Storm
777 6.1 警告
Network
weForms Pro weForms weForms Pro の WordPress 用 weForms におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-0386 2025-01-17 18:26 2024-03-12 Show GitHub Exploit DB Packet Storm
778 8.8 重要
Network
Themeum Tutor LMS Themeum の WordPress 用 Tutor LMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-1751 2025-01-17 18:26 2024-03-13 Show GitHub Exploit DB Packet Storm
779 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. f1203 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の f1203 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-2979 2025-01-17 18:26 2024-03-27 Show GitHub Exploit DB Packet Storm
780 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-3146 2025-01-17 18:26 2024-04-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 24, 2025, 4:45 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
276251 - freebsd
mandrakesoft
redhat
turbolinux
freebsd
mandrake_linux
linux
turbolinux
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument. NVD-CWE-Other
CVE-2000-0186 2008-09-11 04:03 2000-02-28 Show GitHub Exploit DB Packet Storm
276252 - alex_heiphetz_group ezshopper EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. NVD-CWE-Other
CVE-2000-0187 2008-09-11 04:03 2000-02-27 Show GitHub Exploit DB Packet Storm
276253 - alex_heiphetz_group ezshopper EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. NVD-CWE-Other
CVE-2000-0188 2008-09-11 04:03 2000-02-27 Show GitHub Exploit DB Packet Storm
276254 - allaire coldfusion_server ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files. NVD-CWE-Other
CVE-2000-0189 2008-09-11 04:03 2000-03-1 Show GitHub Exploit DB Packet Storm
276255 - aol instant_messenger AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value. NVD-CWE-Other
CVE-2000-0190 2008-09-11 04:03 2000-03-2 Show GitHub Exploit DB Packet Storm
276256 - caldera openlinux The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system. NVD-CWE-Other
CVE-2000-0192 2008-09-11 04:03 2000-03-5 Show GitHub Exploit DB Packet Storm
276257 - corel linux buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters. NVD-CWE-Other
CVE-2000-0194 2008-09-11 04:03 2000-02-24 Show GitHub Exploit DB Packet Storm
276258 - corel linux setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file. NVD-CWE-Other
CVE-2000-0195 2008-09-11 04:03 2000-02-24 Show GitHub Exploit DB Packet Storm
276259 - nmh
redhat
turbolinux
nmh
linux
turbolinux
Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message. NVD-CWE-Other
CVE-2000-0196 2008-09-11 04:03 2000-02-28 Show GitHub Exploit DB Packet Storm
276260 - microsoft windows_nt The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file … NVD-CWE-Other
CVE-2000-0197 2008-09-11 04:03 2000-02-14 Show GitHub Exploit DB Packet Storm