You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
|
Update Date":Jan. 22, 2025, 6:04 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
791 | 4.3 |
警告
Network |
DesDev Inc. | DedeCMS | DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2024-4591 | 2025-01-16 16:05 | 2024-05-7 | Show | GitHub Exploit DB Packet Storm |
792 | 6.1 |
警告
Network |
Metagauss Inc. | eventprime | Metagauss Inc. の WordPress 用 eventprime におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2024-9865 | 2025-01-16 16:05 | 2024-10-24 | Show | GitHub Exploit DB Packet Storm |
793 | 6.1 |
警告
Network |
oretnom23 | customer support system | Oretnom23 の customer support system におけるクロスサイトスクリプティングの脆弱性 |
CWE-79 CWE-79 |
CVE-2023-49973 | 2025-01-16 16:05 | 2023-12-4 | Show | GitHub Exploit DB Packet Storm |
794 | 5.4 |
警告
Network |
Leap13 | Premium Addons for Elementor | Leap13 の WordPress 用 Premium Addons for Elementor におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2024-1680 | 2025-01-16 16:05 | 2024-03-13 | Show | GitHub Exploit DB Packet Storm |
795 | 8.8 |
重要
Network |
code-projects | blood bank management system | codezips の Blood Bank Management System における SQL インジェクションの脆弱性 |
CWE-74 CWE-89 CWE-89 |
CVE-2025-0232 | 2025-01-16 16:03 | 2025-01-5 | Show | GitHub Exploit DB Packet Storm |
796 | 4.8 |
警告
Network |
code-projects | Local Storage Todo App | code-projects の Local Storage Todo App におけるクロスサイトスクリプティングの脆弱性 |
CWE-79 CWE-79 CWE-94 |
CVE-2025-0228 | 2025-01-16 16:02 | 2025-01-5 | Show | GitHub Exploit DB Packet Storm |
797 | 6.1 |
警告
Network |
FreeScout | FreeScout | FreeScout におけるクロスサイトスクリプティングの脆弱性 |
CWE-74 CWE-79 |
CVE-2024-34697 | 2025-01-16 15:49 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
798 | 6.3 |
警告
Network |
FreeScout | FreeScout | FreeScout におけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性 |
CWE-1321 CWE-1321 |
CVE-2024-34698 | 2025-01-16 15:49 | 2024-05-14 | Show | GitHub Exploit DB Packet Storm |
799 | 4.3 |
警告
Network |
Themeum | Tutor LMS | Themeum の WordPress 用 Tutor LMS における認証の欠如に関する脆弱性 |
CWE-862
認証の欠如 |
CVE-2024-1502 | 2025-01-16 15:49 | 2024-03-21 | Show | GitHub Exploit DB Packet Storm |
800 | 4.3 |
警告
Network |
DesDev Inc. | DedeCMS | DesDev Inc. の DedeCMS におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2024-2823 | 2025-01-16 15:49 | 2024-03-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:Jan. 23, 2025, 5:11 a.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
151 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1607 windows_10_1507 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_22h2 windows_11_… |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21321 | 2025-01-22 23:46 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
152 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21320 | 2025-01-22 23:45 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
153 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1607 windows_10_1507 windows_10_1809 windows_10_21h2 windows_10_22h2 windows… |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21319 | 2025-01-22 23:44 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
154 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1607 windows_10_1507 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_22h2 windows_11_… |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21318 | 2025-01-22 23:43 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
155 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2025 windows_server_2022_23h2 windows_10_21h2 windows_10_22h2 windows_11_22h2 windows_11_23h2 windows_11_24h2 windows_server_2022 |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21317 | 2025-01-22 23:42 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
156 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1607 windows_10_1809 windows_10_1507 windows_10_21h2 windows_10_22h2 windows_11_22h2 windows_11_… |
Windows Kernel Memory Information Disclosure Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21316 | 2025-01-22 23:41 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
157 | 7.8 |
HIGH
Local |
microsoft |
windows_server_2025 windows_server_2022_23h2 windows_11_24h2 |
Microsoft Brokering File System Elevation of Privilege Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2025-21315 | 2025-01-22 23:40 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
158 | - | - | - | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. New | - | CVE-2024-57937 | 2025-01-22 22:15 | 2025-01-21 | Show | GitHub Exploit DB Packet Storm | |
159 | 7.3 |
HIGH
Network
-
|
-
|
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() fu…
New
|
CWE-94
|
Code Injection
CVE-2024-13499
|
2025-01-22 20:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
160 | 7.5 |
HIGH
Network
-
|
-
|
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versi…
New
|
CWE-89
|
SQL Injection
CVE-2024-13496
|
2025-01-22 20:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|