Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 22, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
81 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. AC8 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の AC8 ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-4065 2025-01-22 15:37 2024-04-23 Show GitHub Exploit DB Packet Storm
82 8.8 重要
Network
Shenzhen Tenda Technology Co.,Ltd. 4g300 ファームウェア Shenzhen Tenda Technology Co.,Ltd. の 4g300 ファームウェアにおける境界外書き込みに関する脆弱性 New CWE-121
CWE-787
CVE-2024-4169 2025-01-22 15:37 2024-04-25 Show GitHub Exploit DB Packet Storm
83 8.5 重要
Network
cvat computer vision annotation tool cvat の computer vision annotation tool におけるサーバサイドのリクエストフォージェリの脆弱性 New CWE-918
CWE-918
CVE-2024-37164 2025-01-22 15:37 2024-06-13 Show GitHub Exploit DB Packet Storm
84 5.4 警告
Network
exclusiveaddons exclusive addons for elementor exclusiveaddons の WordPress 用 exclusive addons for elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2750 2025-01-22 15:31 2024-05-2 Show GitHub Exploit DB Packet Storm
85 5.5 警告
Local
デル repository manager デルの repository manager におけるパストラバーサルの脆弱性 New CWE-20
CWE-22
CVE-2024-28977 2025-01-22 15:31 2024-04-24 Show GitHub Exploit DB Packet Storm
86 8.8 重要
Network
XWiki xwiki XWiki の xwiki におけるコードインジェクションの脆弱性 New CWE-94
CWE-95
CVE-2024-31984 2025-01-22 15:31 2024-04-10 Show GitHub Exploit DB Packet Storm
87 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows 11
Microsoft Window…
GDI+ のリモート コードが実行される脆弱性 New CWE-190
CWE-noinfo
CVE-2025-21338 2025-01-22 15:31 2025-01-14 Show GitHub Exploit DB Packet Storm
88 8.8 重要
Network
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microsoft Windows Server 2025
Microsoft Windows 11
Microsoft Window…
MapUrlToZone セキュリティ機能のバイパスの脆弱性 New CWE-41
CWE-noinfo
CVE-2025-21332 2025-01-22 15:27 2025-01-14 Show GitHub Exploit DB Packet Storm
89 9.8 緊急
Network
netentsec application security gateway netentsec の application security gateway における SQL インジェクションの脆弱性 New CWE-89
SQLインジェクション
CVE-2024-2022 2025-01-22 15:12 2024-03-1 Show GitHub Exploit DB Packet Storm
90 5.4 警告
Network
wpkoi wpkoi templates for elementor wpkoi の WordPress 用 wpkoi templates for elementor におけるクロスサイトスクリプティングの脆弱性 New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-2136 2025-01-22 15:12 2024-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 22, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
491 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rene Hermenau QR Code Generator allows DOM-Based XSS.This issue affects QR Code Generator: from n… CWE-79
Cross-site Scripting
CVE-2025-23831 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
492 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jobair JB Horizontal Scroller News Ticker allows DOM-Based XSS.This issue affects JB Horizontal S… CWE-79
Cross-site Scripting
CVE-2025-23830 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
493 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OriginalTips.com WordPress Data Guard allows Stored XSS.This issue affects WordPress Data Guard: … CWE-79
Cross-site Scripting
CVE-2025-23828 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
494 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Strx Strx Magic Floating Sidebar Maker allows Stored XSS.This issue affects Strx Magic Floating S… CWE-79
Cross-site Scripting
CVE-2025-23827 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
495 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Predrag Supurovic Stop Comment Spam allows Stored XSS.This issue affects Stop Comment Spam: from … CWE-79
Cross-site Scripting
CVE-2025-23826 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
496 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Thorpe Easy Shortcode Buttons allows Stored XSS.This issue affects Easy Shortcode Buttons: f… CWE-79
Cross-site Scripting
CVE-2025-23825 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
497 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io … CWE-79
Cross-site Scripting
CVE-2025-23824 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
498 - - - Cross-Site Request Forgery (CSRF) vulnerability in jprintf CNZZ&51LA for WordPress allows Cross Site Request Forgery.This issue affects CNZZ&51LA for WordPress: from n/a through 1.0.1. CWE-352
 Origin Validation Error
CVE-2025-23823 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
499 - - - Cross-Site Request Forgery (CSRF) vulnerability in Cornea Alexandru Category Custom Fields allows Cross Site Request Forgery.This issue affects Category Custom Fields: from n/a through 1.0. CWE-352
 Origin Validation Error
CVE-2025-23822 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm
500 - - - Cross-Site Request Forgery (CSRF) vulnerability in Aleapp WP Cookies Alert allows Cross Site Request Forgery.This issue affects WP Cookies Alert: from n/a through 1.1.1. CWE-352
 Origin Validation Error
CVE-2025-23821 2025-01-17 06:15 2025-01-17 Show GitHub Exploit DB Packet Storm