脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-8969 |
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151.
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8968 |
|
mozilla の脆弱性 (CVE-2026-8968)
mozilla に 脆弱性 (CVE-2026-8968) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-8974 |
|
mozilla に バッファオーバーフロー (CVE-2026-8974)
mozilla に 脆弱性 (CVE-2026-8974) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8966 |
|
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151.
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8967 |
|
mozilla に 情報漏洩 (CVE-2026-8967)
mozilla に 脆弱性 (CVE-2026-8967) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-8970 |
|
privilege-escalation に 権限昇格 (CVE-2026-8970)
privilege-escalation に 脆弱性 (CVE-2026-8970) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8972 |
|
privilege-escalation に 権限昇格 (CVE-2026-8972)
privilege-escalation に 脆弱性 (CVE-2026-8972) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8965 |
|
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151.
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8957 |
|
privilege-escalation に 権限昇格 (CVE-2026-8957)
privilege-escalation に 脆弱性 (CVE-2026-8957) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8960 |
|
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151.
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8963 |
|
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151.
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8964 |
|
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151.
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151.
|
| CVE-2026-8958 |
|
mozilla の脆弱性 (CVE-2026-8958)
mozilla に 脆弱性 (CVE-2026-8958) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-8962 |
|
mozilla の脆弱性 (CVE-2026-8962)
mozilla に 脆弱性 (CVE-2026-8962) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-8949 |
|
mozilla の脆弱性 (CVE-2026-8949)
mozilla に 脆弱性 (CVE-2026-8949) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-8954 |
|
mozilla に バッファオーバーフロー (CVE-2026-8954)
mozilla に 脆弱性 (CVE-2026-8954) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-8952 |
|
privilege-escalation に 権限昇格 (CVE-2026-8952)
privilege-escalation に 脆弱性 (CVE-2026-8952) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8955 |
|
privilege-escalation に 権限昇格 (CVE-2026-8955)
privilege-escalation に 脆弱性 (CVE-2026-8955) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8947 |
|
mozilla に 解放後使用 (Use-After-Free) (CVE-2026-8947)
mozilla に 脆弱性 (CVE-2026-8947) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-8946 |
|
mozilla に バッファオーバーフロー (CVE-2026-8946)
mozilla に 脆弱性 (CVE-2026-8946) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-8945 |
|
mozilla の脆弱性 (CVE-2026-8945)
mozilla に 脆弱性 (CVE-2026-8945) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-42099 |
|
sparxsystems の脆弱性 (CVE-2026-42099)
sparxsystems に 脆弱性 (CVE-2026-42099) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-42096 |
|
sparxsystems に 認可不備 (CVE-2026-42096)
sparxsystems に 脆弱性 (CVE-2026-42096) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-23558 |
|
xen の脆弱性 (CVE-2026-23558)
xen に 脆弱性 (CVE-2026-23558) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8912 |
|
wordpress に SQLインジェクション (CVE-2026-8912)
wordpress に SQLインジェクション (CVE-2026-8912) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-7504 |
|
org.keycloak:keycloak-services に オープンリダイレクト (CVE-2026-7504)
org.keycloak:keycloak-services に 脆弱性 (CVE-2026-7504) が存在。機密情報が外部に流出する可能性があります。対策: `26.6.2` 以上に更新。
|
| CVE-2026-7507 |
|
org.keycloak:keycloak-services の脆弱性 (CVE-2026-7507)
org.keycloak:keycloak-services に 脆弱性 (CVE-2026-7507) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `26.6.2` 以上に更新。
|
| CVE-2026-7571 |
|
org.keycloak:keycloak-services の脆弱性 (CVE-2026-7571)
org.keycloak:keycloak-services に 脆弱性 (CVE-2026-7571) が存在。機密情報が外部に流出する可能性があります。対策: `26.6.2` 以上に更新。
|
| CVE-2026-31910 |
|
apache に SSRF (サーバー側リクエスト偽造) (CVE-2026-31910)
apache に SSRF (CVE-2026-31910) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-46586 |
|
apache に コードインジェクション (CVE-2026-46586)
apache に コードインジェクション (CVE-2026-46586) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-31909 |
|
apache に 情報漏洩 (CVE-2026-31909)
apache に 脆弱性 (CVE-2026-31909) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-29226 |
|
apache に SSRF (サーバー側リクエスト偽造) (CVE-2026-29226)
apache に SSRF (CVE-2026-29226) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-47314 |
|
samsung に 境界外書き込み (CVE-2026-47314)
samsung に 境界外書き込み (CVE-2026-47314) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-47311 |
|
samsung の脆弱性 (CVE-2026-47311)
samsung に 脆弱性 (CVE-2026-47311) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-47310 |
|
samsung に 解放後使用 (Use-After-Free) (CVE-2026-47310)
samsung に 脆弱性 (CVE-2026-47310) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-25781 |
|
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
|
| CVE-2026-27648 |
|
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre...
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre...
|
| CVE-2026-33233 |
|
deserialization に コードインジェクション (CVE-2026-33233)
deserialization に コードインジェクション (CVE-2026-33233) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-33232 |
|
dos の脆弱性 (CVE-2026-33232)
dos に 脆弱性 (CVE-2026-33232) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-32323 |
|
privilege-escalation に 権限昇格 (CVE-2026-32323)
privilege-escalation に 脆弱性 (CVE-2026-32323) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-30950 |
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijack...
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session, t...
|
| CVE-2026-27891 |
|
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the f...
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...
|
| CVE-2026-8851 |
|
sqli に SQLインジェクション (CVE-2026-8851)
sqli に SQLインジェクション (CVE-2026-8851) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-47092 |
|
jarrodwatts の脆弱性 (CVE-2026-47092)
jarrodwatts に 脆弱性 (CVE-2026-47092) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-45245 |
|
@steipete/summarize に SSRF (サーバー側リクエスト偽造) (CVE-2026-45245)
@steipete/summarize に SSRF (CVE-2026-45245) が存在。機密情報が外部に流出する可能性があります。対策: `0.15.1` 以上に更新。
|
| CVE-2026-46522 |
|
Magick.NET-Q16-AnyCPU の脆弱性 (CVE-2026-46522)
Magick.NET-Q16-AnyCPU に 脆弱性 (CVE-2026-46522) が存在。不正な操作・情報露出のリスクがあります。対策: `14.13.1` 以上に更新。
|
| CVE-2026-46520 |
|
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
|
| CVE-2026-45553 |
|
nicegui に 情報漏洩 (CVE-2026-45553)
nicegui に 脆弱性 (CVE-2026-45553) が存在。機密情報が外部に流出する可能性があります。``include`` 経由で攻撃可能。対策: `3.12.0` 以上に更新。
|
| CVE-2026-45686 |
|
go.opentelemetry.io/obi の脆弱性 (CVE-2026-45686)
go.opentelemetry.io/obi に 脆弱性 (CVE-2026-45686) が存在。不正な操作・情報露出のリスクがあります。``set`` 経由で攻撃可能。対策: `0.9.0` 以上に更新。
|
| CVE-2026-45685 |
|
go.opentelemetry.io/obi の脆弱性 (CVE-2026-45685)
go.opentelemetry.io/obi に 脆弱性 (CVE-2026-45685) が存在。不正な操作・情報露出のリスクがあります。``parseOpMessage`` 経由で攻撃可能。対策: `0.9.0` 以上に更新。
|