脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: cwe クリア
ID タイトル
CVE-2026-27408 Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
CVE-2026-57343 Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-27430 Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
CVE-2026-57345 Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
CVE-2026-57344 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
CVE-2026-39448 Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
CVE-2026-27060 Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
CVE-2026-27414 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-56037 deserialization に 安全でないデシリアライゼーション (CVE-2026-56037)
deserialization に 脆弱性 (CVE-2026-56037) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-57348 Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
CVE-2026-27412 Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
CVE-2026-42382 Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2025-58902 Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2025-69133 Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69094 Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-69152 wordpress に クロスサイトスクリプティング (CVE-2025-69152)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2025-69152) が存在。不正な操作・情報露出のリスクがあります。
CVE-2025-69153 Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69154 wordpress に クロスサイトスクリプティング (CVE-2025-69154)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2025-69154) が存在。不正な操作・情報露出のリスクがあります。
CVE-2025-69155 Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
CVE-2025-69156 Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
CVE-2026-11946 CVE-2026-11946 の脆弱性 (CVE-2026-11946)
CVE-2026-11946 に 脆弱性 (CVE-2026-11946) が存在。不正な操作・情報露出のリスクがあります。
CVE-2025-69134 wordpress の脆弱性 (CVE-2025-69134)
wordpress に 脆弱性 (CVE-2025-69134) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-9834 wordpress に コマンドインジェクション (CVE-2026-9834)
wordpress に コマンドインジェクション (CVE-2026-9834) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``wp_db_exclude_table`` 経由で攻撃可能。
CVE-2026-8441 wordpress に SQLインジェクション (CVE-2026-8441)
wordpress に SQLインジェクション (CVE-2026-8441) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-14336 CVE-2026-14336 に SSRF (サーバー側リクエスト偽造) (CVE-2026-14336)
CVE-2026-14336 に SSRF (CVE-2026-14336) が存在。データの不正な改ざんを許す可能性があります。`POST /v1/upload/sbom` 経由で攻撃可能。
CVE-2026-13369 wordpress に パストラバーサル (CVE-2026-13369)
wordpress に パストラバーサル (CVE-2026-13369) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-13251 wordpress に パストラバーサル (CVE-2026-13251)
wordpress に パストラバーサル (CVE-2026-13251) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-8147 mlflow の脆弱性 (CVE-2026-8147)
mlflow に 脆弱性 (CVE-2026-8147) が存在。機密情報が外部に流出する可能性があります。``_before_request`` 経由で攻撃可能。対策: `3.13.0rc0` 以上に更新。
CVE-2026-33592 CVE-2026-33592 の脆弱性 (CVE-2026-33592)
CVE-2026-33592 に 脆弱性 (CVE-2026-33592) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-9563 dos の脆弱性 (CVE-2026-9563)
dos に 脆弱性 (CVE-2026-9563) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-14249 wordpress の脆弱性 (CVE-2026-14249)
wordpress に 脆弱性 (CVE-2026-14249) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-5821 wordpress の脆弱性 (CVE-2026-5821)
wordpress に 脆弱性 (CVE-2026-5821) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-57277 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-57278 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-57274 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-57275 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-57276 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-57273 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-13125 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-14415 google の脆弱性 (CVE-2026-14415)
google に 脆弱性 (CVE-2026-14415) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14427 google の脆弱性 (CVE-2026-14427)
google に 脆弱性 (CVE-2026-14427) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14431 google の脆弱性 (CVE-2026-14431)
google に 脆弱性 (CVE-2026-14431) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14428 google の脆弱性 (CVE-2026-14428)
google に 脆弱性 (CVE-2026-14428) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14429 google の脆弱性 (CVE-2026-14429)
google に 脆弱性 (CVE-2026-14429) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14422 google に 境界外読み取り (CVE-2026-14422)
google に 脆弱性 (CVE-2026-14422) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14430 google の脆弱性 (CVE-2026-14430)
google に 脆弱性 (CVE-2026-14430) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14426 google に 解放後使用 (Use-After-Free) (CVE-2026-14426)
google に 脆弱性 (CVE-2026-14426) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14432 google に 解放後使用 (Use-After-Free) (CVE-2026-14432)
google に 脆弱性 (CVE-2026-14432) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14401 google の脆弱性 (CVE-2026-14401)
google に 脆弱性 (CVE-2026-14401) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14412 google の脆弱性 (CVE-2026-14412)
google に 脆弱性 (CVE-2026-14412) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →