脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: languages タグ: auth-bypass クリア
ID タイトル
CVE-2026-82466 Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
CVE-2026-82452 c の脆弱性 (CVE-2026-82452)
c に 脆弱性 (CVE-2026-82452) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-6286 wordpress に クロスサイトスクリプティング (CVE-2026-6286)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-6286) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-77998 CVE-2026-77998 の脆弱性 (CVE-2026-77998)
CVE-2026-77998 に 脆弱性 (CVE-2026-77998) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-56707 Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
CVE-2026-34968 Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
CVE-2026-77915 CVE-2026-77915 の脆弱性 (CVE-2026-77915)
CVE-2026-77915 に 脆弱性 (CVE-2026-77915) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /register` 経由で攻撃可能。
CVE-2026-34741 CVE-2026-34741 の脆弱性 (CVE-2026-34741)
CVE-2026-34741 に 脆弱性 (CVE-2026-34741) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-64961 c の脆弱性 (CVE-2026-64961)
c に 脆弱性 (CVE-2026-64961) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-73683 laravel の脆弱性 (CVE-2026-73683)
laravel に 脆弱性 (CVE-2026-73683) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15426 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
CVE-2026-53977 express の脆弱性 (CVE-2026-53977)
express に 脆弱性 (CVE-2026-53977) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-71248 sqli に SQLインジェクション (CVE-2026-71248)
sqli に SQLインジェクション (CVE-2026-71248) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
CVE-2026-70552 CVE-2026-70552 の脆弱性 (CVE-2026-70552)
CVE-2026-70552 に 脆弱性 (CVE-2026-70552) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-69091 CVE-2026-69091 の脆弱性 (CVE-2026-69091)
CVE-2026-69091 に 脆弱性 (CVE-2026-69091) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-64827 CVE-2026-64827 の脆弱性 (CVE-2026-64827)
CVE-2026-64827 に 脆弱性 (CVE-2026-64827) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-8457 wordpress の脆弱性 (CVE-2026-8457)
wordpress に 脆弱性 (CVE-2026-8457) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15964 wordpress の脆弱性 (CVE-2026-15964)
wordpress に 脆弱性 (CVE-2026-15964) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``wp_ajax_nopriv_ssoprocess_ajax`` 経由で攻撃可能。
CVE-2026-66473 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-15981 wordpress に 認証バイパス (CVE-2026-15981)
wordpress に 認証バイパス (CVE-2026-15981) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-63030 KEV WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVE-2026-55234 Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize ag...
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authen...
CVE-2026-47303 Microsoft.AspNetCore.Authentication.Negotiate の脆弱性 (CVE-2026-47303)
Microsoft.AspNetCore.Authentication.Negotiate に 脆弱性 (CVE-2026-47303) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `8.0.29` 以上に更新。
CVE-2026-14245 wordpress の脆弱性 (CVE-2026-14245)
wordpress に 脆弱性 (CVE-2026-14245) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``form_nonce`` 経由で攻撃可能。
CVE-2026-48618 nodejs の脆弱性 (CVE-2026-48618)
nodejs に 脆弱性 (CVE-2026-48618) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-12417 wordpress の脆弱性 (CVE-2026-12417)
wordpress に 脆弱性 (CVE-2026-12417) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``wp_ajax_nopriv_pravel_change_password`` 経由で攻撃可能。
CVE-2026-10561 langflow に コードインジェクション (CVE-2026-10561)
langflow に コードインジェクション (CVE-2026-10561) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-56346 CVE-2026-56346 の脆弱性 (CVE-2026-56346)
CVE-2026-56346 に 脆弱性 (CVE-2026-56346) が存在。不正な操作・情報露出のリスクがあります。
CVE-2019-25763 wordpress の脆弱性 (CVE-2019-25763)
wordpress に 脆弱性 (CVE-2019-25763) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-55706 c の脆弱性 (CVE-2026-55706)
c に 脆弱性 (CVE-2026-55706) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-54281 @nestjs/platform-fastify に 認可不備 (CVE-2026-54281)
@nestjs/platform-fastify に 脆弱性 (CVE-2026-54281) が存在。不正な操作・情報露出のリスクがあります。`GET /resource` 経由で攻撃可能。対策: `11.1.24` 以上に更新。
CVE-2026-49952 CVE-2026-49952 の脆弱性 (CVE-2026-49952)
CVE-2026-49952 に 脆弱性 (CVE-2026-49952) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-49062 CVE-2026-49062 の脆弱性 (CVE-2026-49062)
CVE-2026-49062 に 脆弱性 (CVE-2026-49062) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-5415 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-42083 Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
CVE-2026-38930 CVE-2026-38930 に SQLインジェクション (CVE-2026-38930)
CVE-2026-38930 に SQLインジェクション (CVE-2026-38930) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-42735 Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
CVE-2026-42745 Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
CVE-2026-46366 phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
CVE-2026-44699 c の脆弱性 (CVE-2026-44699)
c に 脆弱性 (CVE-2026-44699) が存在。不正な操作・情報露出のリスクがあります。対策: `3.3.3` 以上に更新。
CVE-2026-8321 A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function...
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function...
CVE-2026-45223 Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user...
Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user...
CVE-2026-44313 ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-44313)
ssrf に SSRF (CVE-2026-44313) が存在。機密情報が外部に流出する可能性があります。`GET /api/v1/archives/{linkId}` 経由で攻撃可能。
CVE-2013-10075 apache の脆弱性 (CVE-2013-10075)
apache に 脆弱性 (CVE-2013-10075) が存在。機密情報が外部に流出する可能性があります。
CVE-2025-69690 deserialization に 安全でないデシリアライゼーション (CVE-2025-69690)
deserialization に 脆弱性 (CVE-2025-69690) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2024-51092 command-injection に OSコマンドインジェクション (CVE-2024-51092)
command-injection に OSコマンドインジェクション (CVE-2024-51092) が存在。機密情報が外部に流出する可能性があります。``version_netsnmp`` 経由で攻撃可能。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →