Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 27, 2025, 2:02 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
781 4.3 警告
Network
DesDev Inc. DedeCMS DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-4592 2025-01-20 11:23 2024-05-7 Show GitHub Exploit DB Packet Storm
782 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-4122 2025-01-20 11:23 2024-04-24 Show GitHub Exploit DB Packet Storm
783 5.4 警告
Network
WPDeveloper Essential Addons for Elementor WPDeveloper の WordPress 用 Essential Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4449 2025-01-20 11:23 2024-05-14 Show GitHub Exploit DB Packet Storm
784 5.4 警告
Network
Jegtheme Jeg Elementor Kit Jegtheme の WordPress 用 Jeg Elementor Kit におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-87
CVE-2024-3162 2025-01-20 11:22 2024-04-3 Show GitHub Exploit DB Packet Storm
785 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-3006 2025-01-20 11:22 2024-03-27 Show GitHub Exploit DB Packet Storm
786 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2024-3009 2025-01-20 11:22 2024-03-28 Show GitHub Exploit DB Packet Storm
787 5.4 警告
Network
Royal Elementor Addons Royal Elementor Addons and Templates Royal Elementor Addons の WordPress 用 Royal Elementor Addons and Templates におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-3887 2025-01-20 11:22 2024-05-16 Show GitHub Exploit DB Packet Storm
788 5.4 警告
Network
g5plus ultimate bootstrap elements for elementor g5plus の WordPress 用 ultimate bootstrap elements for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2132 2025-01-20 11:20 2024-04-6 Show GitHub Exploit DB Packet Storm
789 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1203 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1203 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-2994 2025-01-20 11:20 2024-03-27 Show GitHub Exploit DB Packet Storm
790 7.8 重要
Local
クアルコム qca6698aq ファームウェア
flight rb5 5g ファームウェア
fastconnect 7800 ファームウェア
fastconnect 6200 ファームウェア
QCA6574AU ファームウェア
QCA6574 ファームウェア
qam8775…
複数のクアルコム製品における脆弱性 CWE-284
CWE-Other
CVE-2024-23351 2025-01-20 11:20 2024-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 27, 2025, 4:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
231 2.8 LOW
Local
- - IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint … New CWE-284
Improper Access Control
CVE-2024-35122 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
232 - - - LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially cr… New - CVE-2019-15690 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
233 5.4 MEDIUM
Network
ayecode ketchup_shortcodes The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sani… Update CWE-79
Cross-site Scripting
CVE-2024-13590 2025-01-25 03:09 2025-01-22 Show GitHub Exploit DB Packet Storm
234 4.3 MEDIUM
Network
quantumcloud wpot The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versio… Update CWE-862
 Missing Authorization
CVE-2024-12879 2025-01-25 03:07 2025-01-22 Show GitHub Exploit DB Packet Storm
235 - - - Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. … New CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2025-24355 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm
236 - - - An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbit… New - CVE-2025-23222 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm
237 - - - ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute… New CWE-134
CWE-749
Use of Externally-Controlled Format String
 Exposed Dangerous Method or Function
CVE-2025-24359 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm
238 - - - Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve… New CWE-200
CWE-862
Information Exposure
 Missing Authorization
CVE-2025-22612 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm
239 - - - Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalat… New CWE-862
 Missing Authorization
CVE-2025-22611 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm
240 - - - Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch t… New CWE-862
 Missing Authorization
CVE-2025-22610 2025-01-25 02:15 2025-01-25 Show GitHub Exploit DB Packet Storm