脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-68959 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-68960 |
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-78478 |
|
wordpress の脆弱性 (CVE-2026-78478)
wordpress に 脆弱性 (CVE-2026-78478) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78637 |
|
CVE-2026-78637 の脆弱性 (CVE-2026-78637)
CVE-2026-78637 に 脆弱性 (CVE-2026-78637) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-78654 |
|
CVE-2026-78654 に コードインジェクション (CVE-2026-78654)
CVE-2026-78654 に コードインジェクション (CVE-2026-78654) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-19892 |
|
wordpress の脆弱性 (CVE-2026-19892)
wordpress に 脆弱性 (CVE-2026-19892) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78685 |
|
CVE-2026-78685 の脆弱性 (CVE-2026-78685)
CVE-2026-78685 に 脆弱性 (CVE-2026-78685) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78682 |
|
CVE-2026-78682 に SSRF (サーバー側リクエスト偽造) (CVE-2026-78682)
CVE-2026-78682 に SSRF (CVE-2026-78682) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-76846 |
|
CVE-2026-76846 の脆弱性 (CVE-2026-76846)
CVE-2026-76846 に 脆弱性 (CVE-2026-76846) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-72696 |
|
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
|
| CVE-2026-72695 |
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
| CVE-2026-72700 |
|
CVE-2026-72700 の脆弱性 (CVE-2026-72700)
CVE-2026-72700 に 脆弱性 (CVE-2026-72700) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56703 |
|
CVE-2026-56703 に コードインジェクション (CVE-2026-56703)
CVE-2026-56703 に コードインジェクション (CVE-2026-56703) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-78284 |
|
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
|
| CVE-2026-78268 |
|
CVE-2026-78268 の脆弱性 (CVE-2026-78268)
CVE-2026-78268 に 脆弱性 (CVE-2026-78268) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-78264 |
|
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
|
| CVE-2026-78282 |
|
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
|
| CVE-2026-77384 |
|
dos の脆弱性 (CVE-2026-77384)
dos に 脆弱性 (CVE-2026-77384) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-78259 |
|
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
|
| CVE-2026-32560 |
|
wordpress の脆弱性 (CVE-2026-32560)
wordpress に 脆弱性 (CVE-2026-32560) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-32556 |
|
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
|
| CVE-2026-7455 |
|
autodesk に 境界外書き込み (CVE-2026-7455)
autodesk に 境界外書き込み (CVE-2026-7455) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-52492 |
|
CVE-2026-52492 の脆弱性 (CVE-2026-52492)
CVE-2026-52492 に 脆弱性 (CVE-2026-52492) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-16783 |
|
autodesk に 境界外書き込み (CVE-2026-16783)
autodesk に 境界外書き込み (CVE-2026-16783) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-75464 |
|
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
|
| CVE-2026-19568 |
|
autodesk の脆弱性 (CVE-2026-19568)
autodesk に 脆弱性 (CVE-2026-19568) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-77567 |
|
laravel に 認証バイパス (CVE-2026-77567)
laravel に 認証バイパス (CVE-2026-77567) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-56135 |
|
c の脆弱性 (CVE-2026-56135)
c に 脆弱性 (CVE-2026-56135) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-75369 |
|
dos に 境界外読み取り (CVE-2026-75369)
dos に 脆弱性 (CVE-2026-75369) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-75368 |
|
dos の脆弱性 (CVE-2026-75368)
dos に 脆弱性 (CVE-2026-75368) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2026-75371 |
|
dos の脆弱性 (CVE-2026-75371)
dos に 脆弱性 (CVE-2026-75371) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-71504 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2025-26238 |
|
CVE-2025-26238 に コードインジェクション (CVE-2025-26238)
CVE-2025-26238 に コードインジェクション (CVE-2025-26238) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2025-26237 |
|
CVE-2025-26237 に コマンドインジェクション (CVE-2025-26237)
CVE-2025-26237 に コマンドインジェクション (CVE-2025-26237) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-76838 |
|
laravel に SSRF (サーバー側リクエスト偽造) (CVE-2026-76838)
laravel に SSRF (CVE-2026-76838) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-71942 |
|
dos の脆弱性 (CVE-2026-71942)
dos に 脆弱性 (CVE-2026-71942) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-76072 |
|
CVE-2026-76072 の脆弱性 (CVE-2026-76072)
CVE-2026-76072 に 脆弱性 (CVE-2026-76072) が存在。データの不正な改ざんを許す可能性があります。
|