脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-66598 |
|
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
|
| CVE-2026-66597 |
|
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
|
| CVE-2026-66601 |
|
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
|
| CVE-2026-66606 |
|
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
|
| CVE-2026-66604 |
|
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
|
| CVE-2026-66607 |
|
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
|
| CVE-2026-66615 |
|
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
|
| CVE-2026-66611 |
|
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
|
| CVE-2026-66616 |
|
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
|
| CVE-2026-66612 |
|
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
|
| CVE-2026-66614 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
|
| CVE-2026-66673 |
|
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
|
| CVE-2026-66605 |
|
CVE-2026-66605 に クロスサイトスクリプティング (CVE-2026-66605)
CVE-2026-66605 に XSS (クロスサイトスクリプティング) (CVE-2026-66605) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-66593 |
|
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
|
| CVE-2026-66649 |
|
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
|
| CVE-2026-66609 |
|
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
|
| CVE-2026-66590 |
|
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
|
| CVE-2026-66581 |
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
|
| CVE-2026-66582 |
|
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
|
| CVE-2025-15688 |
|
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
|
| CVE-2026-66592 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
|
| CVE-2025-15689 |
|
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
|
| CVE-2026-73196 |
|
dos の脆弱性 (CVE-2026-73196)
dos に 脆弱性 (CVE-2026-73196) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-73197 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
| CVE-2026-73198 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
|
| CVE-2026-73199 |
|
dos の脆弱性 (CVE-2026-73199)
dos に 脆弱性 (CVE-2026-73199) が存在。不正な操作・情報露出のリスクがあります。``JOIN_OID`` 経由で攻撃可能。
|
| CVE-2026-13097 |
|
privilege-escalation の脆弱性 (CVE-2026-13097)
privilege-escalation に 脆弱性 (CVE-2026-13097) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-18917 |
|
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
|
| CVE-2026-14947 |
|
path-traversal の脆弱性 (CVE-2026-14947)
path-traversal に 脆弱性 (CVE-2026-14947) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-75948 |
|
CVE-2026-75948 に クロスサイトスクリプティング (CVE-2026-75948)
CVE-2026-75948 に XSS (クロスサイトスクリプティング) (CVE-2026-75948) が存在。不正な操作・情報露出のリスクがあります。``image`` 経由で攻撃可能。
|
| CVE-2026-76564 |
|
CVE-2026-76564 に クロスサイトスクリプティング (CVE-2026-76564)
CVE-2026-76564 に XSS (クロスサイトスクリプティング) (CVE-2026-76564) が存在。不正な操作・情報露出のリスクがあります。`User-Agent header` 経由で攻撃可能。
|
| CVE-2026-76565 |
|
CVE-2026-76565 に クロスサイトスクリプティング (CVE-2026-76565)
CVE-2026-76565 に XSS (クロスサイトスクリプティング) (CVE-2026-76565) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76569 |
|
CVE-2026-76569 に クロスサイトスクリプティング (CVE-2026-76569)
CVE-2026-76569 に XSS (クロスサイトスクリプティング) (CVE-2026-76569) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-74992 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-74992)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-74992) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-15049 |
|
wordpress に 危険なファイルアップロード (CVE-2026-15049)
wordpress に 脆弱性 (CVE-2026-15049) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-19697 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-19697)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-19697) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-75860 |
|
wordpress に 権限昇格 (CVE-2026-75860)
wordpress に 脆弱性 (CVE-2026-75860) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-76956 |
|
dos の脆弱性 (CVE-2026-76956)
dos に 脆弱性 (CVE-2026-76956) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76785 |
|
sqli の脆弱性 (CVE-2026-76785)
sqli に 脆弱性 (CVE-2026-76785) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76783 |
|
sqli の脆弱性 (CVE-2026-76783)
sqli に 脆弱性 (CVE-2026-76783) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76762 |
|
sqli の脆弱性 (CVE-2026-76762)
sqli に 脆弱性 (CVE-2026-76762) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76764 |
|
sqli の脆弱性 (CVE-2026-76764)
sqli に 脆弱性 (CVE-2026-76764) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76923 |
|
dos に 境界外読み取り (CVE-2026-76923)
dos に 脆弱性 (CVE-2026-76923) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-76924 |
|
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76926 |
|
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76927 |
|
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76928 |
|
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76929 |
|
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76890 |
|
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|