脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: vendors タグ: cwe-502 クリア
ID タイトル
CVE-2026-55220 pimcore/pimcore に 安全でないデシリアライゼーション (CVE-2026-55220)
pimcore/pimcore に 脆弱性 (CVE-2026-55220) が存在。不正な操作・情報露出のリスクがあります。``true`` 経由で攻撃可能。対策: `12.3.10` 以上に更新。
CVE-2026-14558 wordpress に 安全でないデシリアライゼーション (CVE-2026-14558)
wordpress に 脆弱性 (CVE-2026-14558) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-78292 Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78286 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-78276 Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78257 Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-47864 deserialization に 安全でないデシリアライゼーション (CVE-2026-47864)
deserialization に 脆弱性 (CVE-2026-47864) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-80428 CVE-2026-80428 に 安全でないデシリアライゼーション (CVE-2026-80428)
CVE-2026-80428 に 脆弱性 (CVE-2026-80428) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-78572 wordpress に 安全でないデシリアライゼーション (CVE-2026-78572)
wordpress に 脆弱性 (CVE-2026-78572) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-77138 CVE-2026-77138 に 安全でないデシリアライゼーション (CVE-2026-77138)
CVE-2026-77138 に 脆弱性 (CVE-2026-77138) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-56095 CVE-2026-56095 に 安全でないデシリアライゼーション (CVE-2026-56095)
CVE-2026-56095 に 脆弱性 (CVE-2026-56095) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-78265 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78262 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-32563 wordpress に 安全でないデシリアライゼーション (CVE-2026-32563)
wordpress に 脆弱性 (CVE-2026-32563) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
CVE-2026-66650 Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVE-2026-0551 wordpress に 安全でないデシリアライゼーション (CVE-2026-0551)
wordpress に 脆弱性 (CVE-2026-0551) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-4703 wordpress に 安全でないデシリアライゼーション (CVE-2026-4703)
wordpress に 脆弱性 (CVE-2026-4703) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-69836 KEV 【KEV】Microsoft deserialization に 安全でないデシリアライゼーション (CVE-2026-69836)
Microsoft deserialization に 脆弱性 (CVE-2026-69836) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2026-73993 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-66672 Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVE-2026-66583 Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-49817 deserialization に 安全でないデシリアライゼーション (CVE-2026-49817)
deserialization に 脆弱性 (CVE-2026-49817) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-49816 deserialization に 安全でないデシリアライゼーション (CVE-2026-49816)
deserialization に 脆弱性 (CVE-2026-49816) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-73389 Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVE-2026-73364 Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-75987 deserialization の脆弱性 (CVE-2026-75987)
deserialization に 脆弱性 (CVE-2026-75987) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-60412 c に 安全でないデシリアライゼーション (CVE-2026-60412)
c に 脆弱性 (CVE-2026-60412) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-60392 c に 安全でないデシリアライゼーション (CVE-2026-60392)
c に 脆弱性 (CVE-2026-60392) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-74012 Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
CVE-2026-73376 Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73380 Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73366 Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2026-73341 Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
CVE-2026-32470 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-66620 Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
CVE-2026-32465 Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
CVE-2024-13784 wordpress に 安全でないデシリアライゼーション (CVE-2024-13784)
wordpress に 脆弱性 (CVE-2024-13784) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-10035 wordpress に 安全でないデシリアライゼーション (CVE-2026-10035)
wordpress に 脆弱性 (CVE-2026-10035) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-16099 wordpress に 安全でないデシリアライゼーション (CVE-2026-16099)
wordpress に 脆弱性 (CVE-2026-16099) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-19826 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
CVE-2026-10571 dos に 安全でないデシリアライゼーション (CVE-2026-10571)
dos に 脆弱性 (CVE-2026-10571) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-66256 apache に 安全でないデシリアライゼーション (CVE-2026-66256)
apache に 脆弱性 (CVE-2026-66256) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-28176 Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
CVE-2026-28149 Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-27380 Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVE-2026-67587 apache に 安全でないデシリアライゼーション (CVE-2026-67587)
apache に 脆弱性 (CVE-2026-67587) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``Callback`` 経由で攻撃可能。
CVE-2026-67260 apache に 安全でないデシリアライゼーション (CVE-2026-67260)
apache に 脆弱性 (CVE-2026-67260) が存在。不正な操作・情報露出のリスクがあります。``awaiting_input`` 経由で攻撃可能。
CVE-2026-59242 apache に 安全でないデシリアライゼーション (CVE-2026-59242)
apache に 脆弱性 (CVE-2026-59242) が存在。不正な操作・情報露出のリスクがあります。`GET /api/v2/{...}/xcomEntries/{key}` 経由で攻撃可能。
CVE-2026-58076 apache に 安全でないデシリアライゼーション (CVE-2026-58076)
apache に 脆弱性 (CVE-2026-58076) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`GET /api/v2/dags/{dag_id}/details` 経由で攻撃可能。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →