Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
961 4.9 警告
Network
ZyXEL DX5401-B1 ファームウェア
DX3300-T0 ファームウェア
ex5401-b0 ファームウェア
EX5600-T1 ファームウェア
DX4510-B1 ファームウェア
EX5401-B1 ファームウェア
EX3510-B1 ファームウェア
EX3510-B0 ファ…
複数の ZyXEL 製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2024-9197 2025-01-22 17:20 2024-12-3 Show GitHub Exploit DB Packet Storm
962 5.3 警告
Network
Fortra FileCatalyst Direct Fortra の FileCatalyst Direct におけるパストラバーサルの脆弱性 CWE-22
CWE-22
CVE-2024-25154 2025-01-22 17:17 2024-03-13 Show GitHub Exploit DB Packet Storm
963 9.8 緊急
Network
The Biosig Project
Fedora Project
libbiosig
Fedora
The Biosig Project の libbiosig 等複数ベンダの製品における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2024-23305 2025-01-22 17:15 2024-02-20 Show GitHub Exploit DB Packet Storm
964 9.8 緊急
Network
dirk1983 chatgpt-wechat-personal dirk1983 の chatgpt-wechat-personal におけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
CWE-918
CVE-2024-27565 2025-01-22 17:08 2024-03-5 Show GitHub Exploit DB Packet Storm
965 5.4 警告
Network
Gonahkar Custom fields shortcode Gonahkar の WordPress 用 Custom fields shortcode におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2023-6809 2025-01-22 17:05 2023-12-13 Show GitHub Exploit DB Packet Storm
966 5.4 警告
Network
Savvy Wordpress Development MyWaze Savvy Wordpress Development の WordPress 用 MyWaze におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-25594 2025-01-22 17:03 2024-02-29 Show GitHub Exploit DB Packet Storm
967 7.8 重要
Local
マイクロソフト Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Server のリモートでコードが実行される脆弱性 CWE-20
CWE-noinfo
CVE-2025-21344 2025-01-22 17:00 2025-01-14 Show GitHub Exploit DB Packet Storm
968 8.8 重要
Network
ZyXEL nwa90ax pro ファームウェア
nwa1123acv3 ファームウェア
nwa220ax-6e ファームウェア
WAX610D ファームウェア
wax300h ファームウェア
WAX510D ファームウェア
wac500h ファームウェア
wac500 ファ…
複数の ZyXEL 製品における脆弱性 CWE-269
CWE-noinfo
CVE-2024-12398 2025-01-22 16:58 2024-12-10 Show GitHub Exploit DB Packet Storm
969 6.6 警告
Physics
マイクロソフト Microsoft Windows Server 2008
Microsoft Windows Server 2019
Microsoft Windows Server 2012
Microsoft Windows 10
Microsoft Window…
Windows デジタル メディアの特権昇格の脆弱性 CWE-125
CWE-noinfo
CVE-2025-21341 2025-01-22 16:57 2025-01-14 Show GitHub Exploit DB Packet Storm
970 5.3 警告
Adjacent
ZyXEL ATP500 ファームウェア
ATP800 ファームウェア
ATP100 ファームウェア
atp700 ファームウェア
atp100w ファームウェア
ATP200 ファームウェア
USG FLEX 100H ファームウェア
usg flex 1…
複数の ZyXEL 製品における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2023-6397 2025-01-22 16:54 2023-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 21, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1361 - - - Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of th… CWE-798
 Use of Hard-coded Credentials
CVE-2025-1143 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1362 - - - A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/Category.php. The manipulation… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-1170 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1363 3.5 LOW
Network
- - A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The m… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2025-1169 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1364 - - - A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php.… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1168 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1365 - - - A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_… CWE-89
CWE-74
SQL Injection
Injection
CVE-2025-1167 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1366 - - - A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The mani… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2025-1166 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1367 - - - SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any… CWE-22
Path Traversal
CVE-2025-25243 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1368 - - - Due to a missing authorization check, an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads to … CWE-862
 Missing Authorization
CVE-2025-25241 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1369 - - - The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting ma… CWE-601
Open Redirect
CVE-2025-24876 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm
1370 - - - SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this … CWE-352
 Origin Validation Error
CVE-2025-24875 2025-02-11 15:15 2025-02-11 Show GitHub Exploit DB Packet Storm