Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 7, 2024, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
81 4.3 警告
Adjacent
gotenna atak plugin gotenna の atak plugin における観測可能な不一致に関する脆弱性 New CWE-203
CWE-204
CVE-2024-41715 2024-10-7 10:21 2024-09-26 Show GitHub Exploit DB Packet Storm
82 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46267 2024-10-7 10:21 2024-10-1 Show GitHub Exploit DB Packet Storm
83 6.5 警告
Network
axios project axios axios project の Node.js 用 axios におけるクロスサイトリクエストフォージェリの脆弱性 Update CWE-352
同一生成元ポリシー違反
CVE-2023-45857 2024-10-7 10:06 2023-11-8 Show GitHub Exploit DB Packet Storm
84 7.5 重要
Network
axios project axios axios におけるリソースの枯渇に関する脆弱性 Update CWE-400
リソースの枯渇
CVE-2021-3749 2024-10-7 10:05 2021-08-30 Show GitHub Exploit DB Packet Storm
85 5.9 警告
Network
axios project axios Axios NPM パッケージにおけるサーバサイドのリクエストフォージェリの脆弱性 Update CWE-918
サーバサイドリクエストフォージェリ
CVE-2020-28168 2024-10-7 10:03 2020-10-29 Show GitHub Exploit DB Packet Storm
86 8.8 重要
Network
WPXPO postx WPXPO の WordPress 用 postx における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-31246 2024-10-7 09:54 2024-06-9 Show GitHub Exploit DB Packet Storm
87 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46259 2024-10-7 09:54 2024-10-1 Show GitHub Exploit DB Packet Storm
88 7.8 重要
Local
randygaul cute png randygaul の cute png における境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2024-46274 2024-10-7 09:54 2024-10-1 Show GitHub Exploit DB Packet Storm
89 4.3 警告
Network
Fluent Forms Contact Form Fluent Forms の WordPress 用 Contact Form における認証の欠如に関する脆弱性 New CWE-285
CWE-862
CVE-2024-5053 2024-10-7 09:54 2024-09-1 Show GitHub Exploit DB Packet Storm
90 4.3 警告
Network
volkov wp accessibility helper volkov の WordPress 用 wp accessibility helper における認証の欠如に関する脆弱性 New CWE-862
認証の欠如
CVE-2024-5987 2024-10-7 09:54 2024-08-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Oct. 7, 2024, 4:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
258781 - inventivetec mediacast Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via… CWE-79
Cross-site Scripting
CVE-2011-2078 2011-09-22 12:31 2011-05-11 Show GitHub Exploit DB Packet Storm
258782 - inventivetec mediacast MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to… CWE-20
 Improper Input Validation 
CVE-2011-2079 2011-09-22 12:31 2011-05-11 Show GitHub Exploit DB Packet Storm
258783 - inventivetec mediacast MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote attackers to obtain sensitive information via unspecif… CWE-200
Information Exposure
CVE-2011-2081 2011-09-22 12:31 2011-05-11 Show GitHub Exploit DB Packet Storm
258784 - apache httpclient Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers … CWE-200
Information Exposure
CVE-2011-1498 2011-09-22 12:30 2011-07-8 Show GitHub Exploit DB Packet Storm
258785 - nagios nagios Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter. CWE-79
Cross-site Scripting
CVE-2011-1523 2011-09-22 12:30 2011-05-4 Show GitHub Exploit DB Packet Storm
258786 - hp performance_insight Unspecified vulnerability in HP Performance Insight 5.0, 5.1x. 5.2x, 5.3x, 5.4, 5.41, and 5.41.002 allows remote attackers to obtain sensitive information via unknown vectors. NVD-CWE-noinfo
CVE-2011-1536 2011-09-22 12:30 2011-04-30 Show GitHub Exploit DB Packet Storm
258787 - hp proliant_support_pack Cross-site scripting (XSS) vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2011-1537 2011-09-22 12:30 2011-05-4 Show GitHub Exploit DB Packet Storm
258788 - hp proliant_support_pack Open redirect vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote authenticated users to redirect other users to arbitrary web sites and conduct phishing attacks via unspecified … CWE-20
 Improper Input Validation 
CVE-2011-1538 2011-09-22 12:30 2011-05-4 Show GitHub Exploit DB Packet Storm
258789 - hp proliant_support_pack Unspecified vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to obtain sensitive information via unknown vectors. NVD-CWE-noinfo
CVE-2011-1539 2011-09-22 12:30 2011-05-4 Show GitHub Exploit DB Packet Storm
258790 - hp system_management_homepage Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authenticated users to execute arbitrary code via unknown vectors. NVD-CWE-noinfo
CVE-2011-1540 2011-09-22 12:30 2011-04-30 Show GitHub Exploit DB Packet Storm