Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
210831 7.5 危険 Digium - Asterisk Open Source の res_pjsip_acl モジュールにおける PJSIP ACL ルールを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-8413 2014-11-26 15:57 2014-11-20 Show GitHub Exploit DB Packet Storm
210832 5 警告 Digium - Asterisk Open Source および Certified Asterisk における ACL 制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-8412 2014-11-26 15:57 2014-11-20 Show GitHub Exploit DB Packet Storm
210833 4.3 警告 jQuery - jQuery UI の Tooltip ウィジェットの jquery.ui.tooltip.js のデフォルトコンテンツオプションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6662 2014-11-26 15:50 2012-11-27 Show GitHub Exploit DB Packet Storm
210834 3.5 注意 Liferay - Liferay Portal Enterprise Edition におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8349 2014-11-26 15:27 2014-11-14 Show GitHub Exploit DB Packet Storm
210835 7.1 危険 Xen プロジェクト - Xen の arch/x86/mm.c 内の do_mmu_update 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-9030 2014-11-26 15:20 2014-11-20 Show GitHub Exploit DB Packet Storm
210836 4 警告 MantisBT Group - MantisBT における $g_download_attachments_threshold および $g_view_attachments_threshold の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-8988 2014-11-26 13:46 2014-11-16 Show GitHub Exploit DB Packet Storm
210837 3.5 注意 MantisBT Group - MantisBT の Configuration Report ページのフィルタのセレクションリストにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8986 2014-11-26 13:45 2014-06-1 Show GitHub Exploit DB Packet Storm
210838 5 警告 ARM Ltd. (旧 Offspark) - PolarSSL におけるダウングレード攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2014-8627 2014-11-26 11:57 2014-10-22 Show GitHub Exploit DB Packet Storm
210839 6.4 警告 Canonical - Ubuntu の apparmor パッケージの apparmor_parser における AppArmor ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1424 2014-11-25 20:32 2014-11-20 Show GitHub Exploit DB Packet Storm
210840 5 警告 Moodle - Moodle の LTI モジュールにおける任意のメッセージの生成を誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2014-9060 2014-11-25 18:39 2014-11-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
251961 8.8 HIGH
Network
hasanmovahed duplicate_title_validate Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hasan Movahed Duplicate Title Validate allows Blind SQL Injection.This issue affects Duplicate Ti… CWE-89
SQL Injection
CVE-2024-49623 2024-10-24 23:18 2024-10-20 Show GitHub Exploit DB Packet Storm
251962 5.4 MEDIUM
Network
mdabdulkader easy_addons_for_elementor Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Md Abdul Kader Easy Addons for Elementor allows Stored XSS.This issue affects Easy Addons … CWE-79
Cross-site Scripting
CVE-2024-49631 2024-10-24 23:12 2024-10-20 Show GitHub Exploit DB Packet Storm
251963 7.8 HIGH
Local
sangoma certified_asterisk
asterisk
An issue was discovered in Sangoma Asterisk through 18.20.0, 19.x and 20.x through 20.5.0, and 21.x through 21.0.0, and Certified Asterisk through 18.9-cert5. In manager.c, the functions action_getco… CWE-22
Path Traversal
CVE-2024-49215 2024-10-24 23:10 2024-10-21 Show GitHub Exploit DB Packet Storm
251964 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't return OOB skb in manage_oob(). syzbot reported use-after-free in unix_stream_recv_urg(). [0] The scenario is … CWE-416
 Use After Free
CVE-2024-47711 2024-10-24 23:03 2024-10-21 Show GitHub Exploit DB Packet Storm
251965 9.8 CRITICAL
Network
elecom wab-i1750-ps_firmware
wab-s1167-ps_firmware
Stack-based buffer overflow vulnerability exists in WAB-I1750-PS and WAB-S1167-PS. By processing a specially crafted HTTP request, arbitrary code may be executed. CWE-787
 Out-of-bounds Write
CVE-2024-43689 2024-10-24 23:02 2024-10-21 Show GitHub Exploit DB Packet Storm
251966 7.5 HIGH
Network
wellchoose administrative_management_system Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server. CWE-22
Path Traversal
CVE-2024-10200 2024-10-24 22:57 2024-10-21 Show GitHub Exploit DB Packet Storm
251967 7.2 HIGH
Network
total-soft ts_poll The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks CWE-89
SQL Injection
CVE-2024-8625 2024-10-24 22:56 2024-10-21 Show GitHub Exploit DB Packet Storm
251968 8.8 HIGH
Network
wellchoose administrative_management_system Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-10201 2024-10-24 22:56 2024-10-21 Show GitHub Exploit DB Packet Storm
251969 8.8 HIGH
Network
wellchoose administrative_management_system Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. CWE-78
OS Command 
CVE-2024-10202 2024-10-24 22:55 2024-10-21 Show GitHub Exploit DB Packet Storm
251970 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netkit: Assign missing bpf_net_context During the introduction of struct bpf_net_context handling for XDP-redirect, the netkit dr… CWE-476
 NULL Pointer Dereference
CVE-2024-47708 2024-10-24 22:45 2024-10-21 Show GitHub Exploit DB Packet Storm