脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82452 |
|
c の脆弱性 (CVE-2026-82452)
c に 脆弱性 (CVE-2026-82452) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-6286 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-6286)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-6286) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-77998 |
|
CVE-2026-77998 の脆弱性 (CVE-2026-77998)
CVE-2026-77998 に 脆弱性 (CVE-2026-77998) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-77915 |
|
CVE-2026-77915 の脆弱性 (CVE-2026-77915)
CVE-2026-77915 に 脆弱性 (CVE-2026-77915) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /register` 経由で攻撃可能。
|
| CVE-2026-34741 |
|
CVE-2026-34741 の脆弱性 (CVE-2026-34741)
CVE-2026-34741 に 脆弱性 (CVE-2026-34741) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2026-64961 |
|
c の脆弱性 (CVE-2026-64961)
c に 脆弱性 (CVE-2026-64961) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-73683 |
|
laravel の脆弱性 (CVE-2026-73683)
laravel に 脆弱性 (CVE-2026-73683) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-15426 |
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
| CVE-2026-53977 |
|
express の脆弱性 (CVE-2026-53977)
express に 脆弱性 (CVE-2026-53977) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-71248 |
|
sqli に SQLインジェクション (CVE-2026-71248)
sqli に SQLインジェクション (CVE-2026-71248) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7520 |
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
| CVE-2026-71206 |
|
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
|
| CVE-2026-6627 |
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-70552 |
|
CVE-2026-70552 の脆弱性 (CVE-2026-70552)
CVE-2026-70552 に 脆弱性 (CVE-2026-70552) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-69091 |
|
CVE-2026-69091 の脆弱性 (CVE-2026-69091)
CVE-2026-69091 に 脆弱性 (CVE-2026-69091) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-64827 |
|
CVE-2026-64827 の脆弱性 (CVE-2026-64827)
CVE-2026-64827 に 脆弱性 (CVE-2026-64827) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-8457 |
|
wordpress の脆弱性 (CVE-2026-8457)
wordpress に 脆弱性 (CVE-2026-8457) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-15964 |
|
wordpress の脆弱性 (CVE-2026-15964)
wordpress に 脆弱性 (CVE-2026-15964) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``wp_ajax_nopriv_ssoprocess_ajax`` 経由で攻撃可能。
|
| CVE-2026-66473 |
|
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
|
| CVE-2026-15981 |
|
wordpress に 認証バイパス (CVE-2026-15981)
wordpress に 認証バイパス (CVE-2026-15981) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-63030 KEV |
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
| CVE-2026-55234 |
|
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize ag...
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authen...
|
| CVE-2026-47303 |
|
Microsoft.AspNetCore.Authentication.Negotiate の脆弱性 (CVE-2026-47303)
Microsoft.AspNetCore.Authentication.Negotiate に 脆弱性 (CVE-2026-47303) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `8.0.29` 以上に更新。
|
| CVE-2026-14245 |
|
wordpress の脆弱性 (CVE-2026-14245)
wordpress に 脆弱性 (CVE-2026-14245) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``form_nonce`` 経由で攻撃可能。
|
| CVE-2026-48618 |
|
nodejs の脆弱性 (CVE-2026-48618)
nodejs に 脆弱性 (CVE-2026-48618) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-12417 |
|
wordpress の脆弱性 (CVE-2026-12417)
wordpress に 脆弱性 (CVE-2026-12417) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``wp_ajax_nopriv_pravel_change_password`` 経由で攻撃可能。
|
| CVE-2026-10561 |
|
langflow に コードインジェクション (CVE-2026-10561)
langflow に コードインジェクション (CVE-2026-10561) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-56346 |
|
CVE-2026-56346 の脆弱性 (CVE-2026-56346)
CVE-2026-56346 に 脆弱性 (CVE-2026-56346) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2019-25763 |
|
wordpress の脆弱性 (CVE-2019-25763)
wordpress に 脆弱性 (CVE-2019-25763) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-55706 |
|
c の脆弱性 (CVE-2026-55706)
c に 脆弱性 (CVE-2026-55706) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54281 |
|
@nestjs/platform-fastify に 認可不備 (CVE-2026-54281)
@nestjs/platform-fastify に 脆弱性 (CVE-2026-54281) が存在。不正な操作・情報露出のリスクがあります。`GET /resource` 経由で攻撃可能。対策: `11.1.24` 以上に更新。
|
| CVE-2026-49952 |
|
CVE-2026-49952 の脆弱性 (CVE-2026-49952)
CVE-2026-49952 に 脆弱性 (CVE-2026-49952) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-49062 |
|
CVE-2026-49062 の脆弱性 (CVE-2026-49062)
CVE-2026-49062 に 脆弱性 (CVE-2026-49062) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5415 |
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
| CVE-2026-42083 |
|
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
|
| CVE-2026-38930 |
|
CVE-2026-38930 に SQLインジェクション (CVE-2026-38930)
CVE-2026-38930 に SQLインジェクション (CVE-2026-38930) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-42735 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
|
| CVE-2026-42745 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
|
| CVE-2026-46366 |
|
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
|
| CVE-2026-44699 |
|
c の脆弱性 (CVE-2026-44699)
c に 脆弱性 (CVE-2026-44699) が存在。不正な操作・情報露出のリスクがあります。対策: `3.3.3` 以上に更新。
|
| CVE-2026-8321 |
|
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function...
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function...
|
| CVE-2026-45223 |
|
Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user...
Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user...
|
| CVE-2026-44313 |
|
ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-44313)
ssrf に SSRF (CVE-2026-44313) が存在。機密情報が外部に流出する可能性があります。`GET /api/v1/archives/{linkId}` 経由で攻撃可能。
|
| CVE-2013-10075 |
|
apache の脆弱性 (CVE-2013-10075)
apache に 脆弱性 (CVE-2013-10075) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2025-69690 |
|
deserialization に 安全でないデシリアライゼーション (CVE-2025-69690)
deserialization に 脆弱性 (CVE-2025-69690) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2024-51092 |
|
command-injection に OSコマンドインジェクション (CVE-2024-51092)
command-injection に OSコマンドインジェクション (CVE-2024-51092) が存在。機密情報が外部に流出する可能性があります。``version_netsnmp`` 経由で攻撃可能。
|