Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
861 7.8 重要
Local
GLPI-PROJECT.ORG glpi agent GLPI-PROJECT.ORG の glpi agent における権限管理に関する脆弱性 CWE-269
CWE-269
CVE-2024-28241 2025-01-23 11:43 2024-04-25 Show GitHub Exploit DB Packet Storm
862 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC7 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC7 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-2892 2025-01-23 11:43 2024-03-26 Show GitHub Exploit DB Packet Storm
863 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC7 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC7 ファームウェアにおける OS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2024-2897 2025-01-23 11:43 2024-03-26 Show GitHub Exploit DB Packet Storm
864 5.4 警告
Network
WPDeveloper essential blocks WPDeveloper の WordPress 用 essential blocks におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-31306 2025-01-23 11:43 2024-04-7 Show GitHub Exploit DB Packet Storm
865 5.4 警告
Network
Jegtheme Jeg Elementor Kit Jegtheme の WordPress 用 Jeg Elementor Kit におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-32721 2025-01-23 11:43 2024-04-24 Show GitHub Exploit DB Packet Storm
866 8.8 重要
Network
Themeum Tutor LMS Themeum の WordPress 用 Tutor LMS における認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-4352 2025-01-23 11:43 2024-05-16 Show GitHub Exploit DB Packet Storm
867 9.8 緊急
Network
Shenzhen Tenda Technology Co.,Ltd. AC18 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC18 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2024-57575 2025-01-23 11:43 2025-01-16 Show GitHub Exploit DB Packet Storm
868 8.8 重要
Network
jfinaloa project jfinaloa jfinaloa project の jfinaloa における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-57775 2025-01-23 11:43 2025-01-16 Show GitHub Exploit DB Packet Storm
869 4.3 警告
Network
Shenzhen Tenda Technology Co.,Ltd. AC18 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC18 ファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2024-2560 2025-01-23 11:42 2024-03-17 Show GitHub Exploit DB Packet Storm
870 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC7 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC7 ファームウェアにおける境界外書き込みに関する脆弱性 CWE-121
CWE-787
CVE-2024-2893 2025-01-23 11:42 2024-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 31, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275411 - juniper junos Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default U… CWE-79
Cross-site Scripting
CVE-2009-3485 2009-10-5 13:00 2009-10-1 Show GitHub Exploit DB Packet Storm
275412 - juniper junos Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to … CWE-79
Cross-site Scripting
CVE-2009-3486 2009-10-5 13:00 2009-10-1 Show GitHub Exploit DB Packet Storm
275413 - allisclear clear_content Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information … CWE-22
Path Traversal
CVE-2009-3538 2009-10-5 13:00 2009-10-3 Show GitHub Exploit DB Packet Storm
275414 - yourfreeworld ultra_classifieds_pro Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php an… CWE-79
Cross-site Scripting
CVE-2009-3539 2009-10-5 13:00 2009-10-3 Show GitHub Exploit DB Packet Storm
275415 - yourfreeworld ultra_classifieds_pro Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenan… CWE-79
Cross-site Scripting
CVE-2009-3540 2009-10-5 13:00 2009-10-3 Show GitHub Exploit DB Packet Storm
275416 - ibm informix_dynamic_server IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failur… CWE-399
 Resource Management Errors
CVE-2009-3470 2009-10-3 13:00 2009-09-30 Show GitHub Exploit DB Packet Storm
275417 - juniper junos Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID pa… CWE-79
Cross-site Scripting
CVE-2009-3487 2009-10-2 13:00 2009-10-1 Show GitHub Exploit DB Packet Storm
275418 - kinfusion com_sportfusion SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter… CWE-89
SQL Injection
CVE-2009-3491 2009-10-2 13:00 2009-10-1 Show GitHub Exploit DB Packet Storm
275419 - ibm installation_manager Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers t… CWE-94
Code Injection
CVE-2009-3518 2009-10-2 13:00 2009-10-2 Show GitHub Exploit DB Packet Storm
275420 - ibm tivoli_composite_application_manager_for_wesbsphere Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary… CWE-79
Cross-site Scripting
CVE-2009-3521 2009-10-2 02:00 2009-10-2 Show GitHub Exploit DB Packet Storm