Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 7, 2024, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
81 4.3 警告
Adjacent
gotenna atak plugin gotenna の atak plugin における観測可能な不一致に関する脆弱性 New CWE-203
CWE-204
CVE-2024-41715 2024-10-7 10:21 2024-09-26 Show GitHub Exploit DB Packet Storm
82 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46267 2024-10-7 10:21 2024-10-1 Show GitHub Exploit DB Packet Storm
83 6.5 警告
Network
axios project axios axios project の Node.js 用 axios におけるクロスサイトリクエストフォージェリの脆弱性 Update CWE-352
同一生成元ポリシー違反
CVE-2023-45857 2024-10-7 10:06 2023-11-8 Show GitHub Exploit DB Packet Storm
84 7.5 重要
Network
axios project axios axios におけるリソースの枯渇に関する脆弱性 Update CWE-400
リソースの枯渇
CVE-2021-3749 2024-10-7 10:05 2021-08-30 Show GitHub Exploit DB Packet Storm
85 5.9 警告
Network
axios project axios Axios NPM パッケージにおけるサーバサイドのリクエストフォージェリの脆弱性 Update CWE-918
サーバサイドリクエストフォージェリ
CVE-2020-28168 2024-10-7 10:03 2020-10-29 Show GitHub Exploit DB Packet Storm
86 8.8 重要
Network
WPXPO postx WPXPO の WordPress 用 postx における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-31246 2024-10-7 09:54 2024-06-9 Show GitHub Exploit DB Packet Storm
87 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46259 2024-10-7 09:54 2024-10-1 Show GitHub Exploit DB Packet Storm
88 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46274 2024-10-7 09:54 2024-10-1 Show GitHub Exploit DB Packet Storm
89 4.3 警告
Network
Fluent Forms Contact Form Fluent Forms の WordPress 用 Contact Form における認証の欠如に関する脆弱性 New CWE-285
CWE-862
CVE-2024-5053 2024-10-7 09:54 2024-09-1 Show GitHub Exploit DB Packet Storm
90 4.3 警告
Network
volkov wp accessibility helper volkov の WordPress 用 wp accessibility helper における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-5987 2024-10-7 09:54 2024-08-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Oct. 7, 2024, 4:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
258771 - tibco spotfire_analytics_server
spotfire_server
Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attac… NVD-CWE-noinfo
CVE-2011-3134 2011-09-23 12:34 2011-09-3 Show GitHub Exploit DB Packet Storm
258772 - geoff_wong hammerhead hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file. CWE-59
Link Following
CVE-2011-3204 2011-09-23 12:34 2011-09-7 Show GitHub Exploit DB Packet Storm
258773 - bcfg2 bcfg2 The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client. CWE-20
 Improper Input Validation 
CVE-2011-3211 2011-09-23 12:34 2011-09-16 Show GitHub Exploit DB Packet Storm
258774 - ibm lotus_domino Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to … CWE-79
Cross-site Scripting
CVE-2011-3576 2011-09-23 12:34 2011-09-19 Show GitHub Exploit DB Packet Storm
258775 - chyrp chyrp upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2745 2011-09-22 12:32 2011-07-27 Show GitHub Exploit DB Packet Storm
258776 - citrix access_gateway Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-2882 2011-09-22 12:32 2011-07-22 Show GitHub Exploit DB Packet Storm
258777 - hp network_node_manager_i Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors. NVD-CWE-noinfo
CVE-2011-1855 2011-09-22 12:31 2011-05-14 Show GitHub Exploit DB Packet Storm
258778 - webmin webmin Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related … CWE-79
Cross-site Scripting
CVE-2011-1937 2011-09-22 12:31 2011-06-1 Show GitHub Exploit DB Packet Storm
258779 - inventivetec mediacast MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by reading an unspecified password data store, a different… CWE-200
Information Exposure
CVE-2011-2076 2011-09-22 12:31 2011-05-11 Show GitHub Exploit DB Packet Storm
258780 - inventivetec mediacast The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections only from 127.0.0.1,… CWE-16
Configuration
CVE-2011-2077 2011-09-22 12:31 2011-05-11 Show GitHub Exploit DB Packet Storm