脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: operating-systems タグ: rce クリア
ID タイトル
CVE-2026-69665 SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
CVE-2026-68062 SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
CVE-2026-64878 tenable に OSコマンドインジェクション (CVE-2026-64878)
tenable に OSコマンドインジェクション (CVE-2026-64878) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-8505 langflow の脆弱性 (CVE-2026-8505)
langflow に 脆弱性 (CVE-2026-8505) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-8481 c に コードインジェクション (CVE-2026-8481)
c に コードインジェクション (CVE-2026-8481) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /api/v1/validate/code` 経由で攻撃可能。
CVE-2026-8476 langflow に 安全でないデシリアライゼーション (CVE-2026-8476)
langflow に 脆弱性 (CVE-2026-8476) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-13448 langflow の脆弱性 (CVE-2026-13448)
langflow に 脆弱性 (CVE-2026-13448) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the...
CVE-2026-47908 Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
CVE-2026-47907 Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
CVE-2026-47906 Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
CVE-2026-8855 dos に コードインジェクション (CVE-2026-8855)
dos に コードインジェクション (CVE-2026-8855) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-43941 electerm の脆弱性 (CVE-2026-43941)
electerm に 脆弱性 (CVE-2026-43941) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``shell.openExternal`` 経由で攻撃可能。
CVE-2026-43208 linux の脆弱性 (CVE-2026-43208)
linux に 脆弱性 (CVE-2026-43208) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-43205 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: validate...
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: validate...
CVE-2026-43197 linux の脆弱性 (CVE-2026-43197)
linux に 脆弱性 (CVE-2026-43197) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-43185 linux の脆弱性 (CVE-2026-43185)
linux に 脆弱性 (CVE-2026-43185) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-43125 linux に 境界外書き込み (CVE-2026-43125)
linux に 境界外書き込み (CVE-2026-43125) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-43067 linux の脆弱性 (CVE-2026-43067)
linux に 脆弱性 (CVE-2026-43067) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-26956 vm2-project の脆弱性 (CVE-2026-26956)
vm2-project に 脆弱性 (CVE-2026-26956) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``catch`` 経由で攻撃可能。
CVE-2026-43038 linux の脆弱性 (CVE-2026-43038)
linux に 脆弱性 (CVE-2026-43038) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-42249 path-traversal に パストラバーサル (CVE-2026-42249)
path-traversal に パストラバーサル (CVE-2026-42249) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-7355 Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7356 Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7358 Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7348 Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7336 Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7335 Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2009-0238 KEV 【KEV】Microsoft office に コードインジェクション (CVE-2009-0238)
Microsoft office に コードインジェクション (CVE-2009-0238) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2026-34621 KEV 【KEV】Adobe acrobat-and-reader の脆弱性 (CVE-2026-34621)
Adobe acrobat-and-reader に 脆弱性 (CVE-2026-34621) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2026-3843 sqli に SQLインジェクション (CVE-2026-3843)
sqli に SQLインジェクション (CVE-2026-3843) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2023-6377 privilege-escalation に 境界外読み取り (CVE-2023-6377)
privilege-escalation に 脆弱性 (CVE-2023-6377) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2023-36884 KEV 【KEV】Microsoft windows の脆弱性 (CVE-2023-36884)
Microsoft windows に 脆弱性 (CVE-2023-36884) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2016-8735 KEV 【KEV】Apache tomcat の脆弱性 (CVE-2016-8735)
Apache tomcat に 脆弱性 (CVE-2016-8735) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2023-21823 KEV 【KEV】Microsoft windows の脆弱性 (CVE-2023-21823)
Microsoft windows に 脆弱性 (CVE-2023-21823) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2023-25136 openbsd の脆弱性 (CVE-2023-25136)
openbsd に 脆弱性 (CVE-2023-25136) が存在。不正な操作・情報露出のリスクがあります。
CVE-2022-41128 KEV 【KEV】Microsoft windows に 境界外書き込み (CVE-2022-41128)
Microsoft windows に 境界外書き込み (CVE-2022-41128) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2022-36534 syncovery に コマンドインジェクション (CVE-2022-36534)
syncovery に コマンドインジェクション (CVE-2022-36534) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2022-30190 KEV 【KEV】Microsoft windows の脆弱性 (CVE-2022-30190)
Microsoft windows に 脆弱性 (CVE-2022-30190) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2022-28944 emcosoftware の脆弱性 (CVE-2022-28944)
emcosoftware に 脆弱性 (CVE-2022-28944) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2018-7602 KEV 【KEV】Drupal core に コードインジェクション (CVE-2018-7602)
Drupal core に コードインジェクション (CVE-2018-7602) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2022-24512 Microsoft.NETCore.App.Runtime.linux-arm に コードインジェクション (CVE-2022-24512)
Microsoft.NETCore.App.Runtime.linux-arm に コードインジェクション (CVE-2022-24512) が存在。不正な操作・情報露出のリスクがあります。対策: `6.0.3` 以上に更新。
CVE-2020-1938 KEV 【KEV】org.apache.tomcat.embed:tomcat-embed-core に 権限昇格 (CVE-2020-1938)
org.apache.tomcat.embed:tomcat-embed-core に 脆弱性 (CVE-2020-1938) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。対策: `7.0.100` 以上に更新。
CVE-2018-8174 KEV 【KEV】Microsoft windows に 境界外書き込み (CVE-2018-8174)
Microsoft windows に 境界外書き込み (CVE-2018-8174) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2021-42638 printerlogic に コマンドインジェクション (CVE-2021-42638)
printerlogic に コマンドインジェクション (CVE-2021-42638) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2021-42631 printerlogic に 安全でないデシリアライゼーション (CVE-2021-42631)
printerlogic に 脆弱性 (CVE-2021-42631) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2021-42635 printerlogic の脆弱性 (CVE-2021-42635)
printerlogic に 脆弱性 (CVE-2021-42635) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →