Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 22, 2025, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
791 7.8 重要
Local
クアルコム QCA6595 ファームウェア
qam8650p ファームウェア
fastconnect 6700 ファームウェア
QCA6574A ファームウェア
qam8775p ファームウェア
flight rb5 5g ファームウェア
qam8255p ファームウェア<…
複数のクアルコム製品における解放済みメモリの使用に関する脆弱性 CWE-416
CWE-416
CVE-2024-23354 2025-01-16 12:29 2024-05-6 Show GitHub Exploit DB Packet Storm
792 7.8 重要
Local
マイクロソフト Microsoft Excel
Microsoft 365 Apps
Microsoft Office Online Server
Microsoft Office
Microsoft Excel のリモートでコードが実行される脆弱性 CWE-502
CWE-noinfo
CVE-2024-30042 2025-01-16 12:27 2024-05-14 Show GitHub Exploit DB Packet Storm
793 7.5 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server 2025
Microsoft Window…
Microsoft Message Queuing (MSMQ) のサービス拒否の脆弱性 CWE-400
CWE-noinfo
CVE-2024-49096 2025-01-16 12:20 2024-12-10 Show GitHub Exploit DB Packet Storm
794 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server 2025
Microsoft Window…
Windows 共通ログ ファイル システム ドライバーの特権の昇格の脆弱性 CWE-126
CWE-noinfo
CVE-2024-49088 2025-01-16 12:15 2024-12-10 Show GitHub Exploit DB Packet Storm
795 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2025
Microsoft Windows Server 2008
Microso…
Windows ルーティングとリモート アクセス サービス (RRAS) のリモートでコードが実行される脆弱性 CWE-122
CWE-190
CWE-noinfo
CVE-2024-49085 2025-01-16 12:12 2024-12-10 Show GitHub Exploit DB Packet Storm
796 6.8 警告
Physics
マイクロソフト Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows 11
Microsoft Windows Server 2025
Microsoft Window…
Windows モバイル ブロードバンド ドライバーの特権昇格の脆弱性 CWE-125
CWE-190
CWE-noinfo
CVE-2024-49078 2025-01-16 12:04 2024-12-10 Show GitHub Exploit DB Packet Storm
797 7 重要
Local
The Dimensional Gate Co. Linux Ratfor Linux Ratfor におけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2024-55577 2025-01-16 11:55 2025-01-15 Show GitHub Exploit DB Packet Storm
798 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. fh1205 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の fh1205 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-3007 2025-01-16 11:44 2024-03-27 Show GitHub Exploit DB Packet Storm
799 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. W15E ファームウェア Shenzhen Tenda Technology Co.,Ltd. の W15E ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-4118 2025-01-16 11:44 2024-04-24 Show GitHub Exploit DB Packet Storm
800 8.8 重要
Network
ThimPress LearnPress ThimPress の WordPress 用 LearnPress における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2024-4397 2025-01-16 11:44 2024-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 22, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
91 6.1 MEDIUM
Network
- - The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on a function. This makes… New CWE-352
 Origin Validation Error
CVE-2024-13444 2025-01-21 20:15 2025-01-21 Show GitHub Exploit DB Packet Storm
92 5.3 MEDIUM
Network
- - The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, … New CWE-89
SQL Injection
CVE-2024-13230 2025-01-21 20:15 2025-01-21 Show GitHub Exploit DB Packet Storm
93 6.4 MEDIUM
Network
- - The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 1.2 due to insufficient input saniti… New CWE-79
Cross-site Scripting
CVE-2024-11226 2025-01-21 20:15 2025-01-21 Show GitHub Exploit DB Packet Storm
94 - - - In the Linux kernel, the following vulnerability has been resolved: ovl: support encoding fid from inode with no alias Dmitry Safonov reported that a WARN_ON() assertion can be trigered by userspac… New - CVE-2025-21654 2025-01-21 20:15 2025-01-19 Show GitHub Exploit DB Packet Storm
95 - - - A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed … New CWE-400
 Uncontrolled Resource Consumption
CVE-2025-23184 2025-01-21 19:15 2025-01-21 Show GitHub Exploit DB Packet Storm
96 - - - NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified. New - CVE-2024-6466 2025-01-21 19:15 2025-01-21 Show GitHub Exploit DB Packet Storm
97 6.1 MEDIUM
Network
- - The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization a… New CWE-79
Cross-site Scripting
CVE-2024-13404 2025-01-21 19:15 2025-01-21 Show GitHub Exploit DB Packet Storm
98 5.3 MEDIUM
Network
- - The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and w… New CWE-862
 Missing Authorization
CVE-2024-12104 2025-01-21 19:15 2025-01-21 Show GitHub Exploit DB Packet Storm
99 6.1 MEDIUM
Network
- - The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_optio… New CWE-352
 Origin Validation Error
CVE-2024-12005 2025-01-21 19:15 2025-01-21 Show GitHub Exploit DB Packet Storm
100 6.4 MEDIUM
Network
- - The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output e… New CWE-79
Cross-site Scripting
CVE-2025-0371 2025-01-21 18:15 2025-01-21 Show GitHub Exploit DB Packet Storm